QID 590676

Date Published: 2022-03-17

QID 590676: Siemens SCALANCE W1750D (Update B) Multiple Vulnerabilities (ICSA-21-131-14)

AFFECTED PRODUCTS
The following versions of SCALANCE W1750D, a software management platform, are affected:
SCALANCE W1750D: All versions prior to 8.7.0
SCALANCE W1750D: v8.7.0 and later and prior to v8.7.1.3 (Only affected by CVE-2020-24635, CVE-2020-24636, CVE-2021-25145, CVE-2021-25146, CVE-2021-25155, CVE-2021-25156, CVE-2021-25157, CVE-2021-25158, CVE-2021-25159, CVE-2021-25160, CVE-2021-25161, and CVE-2021-25162).

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system, fully compromise the underlying operating system, overwrite sensitive system files, create a denial-of-service condition, execute arbitrary script code in a victims browser, read arbitrary files off the underlying file system, create an attacker named directory, corrupt backup files, or obtain sensitive information.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-131-14 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-131-14 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-131-14