QID 591122

Date Published: 2022-10-14

QID 591122: Siemens SCALANCE X-200 Authentication Bypass Vulnerability (ICSA-13-274-01,ssa-176087)

AFFECTED PRODUCTS
Siemens reports that the vulnerability affects the following versions: SCALANCE X-200 switch family with firmware version prior to V4.5.0. SCALANCE X-200IRT (Isochronous Real-Time) switch family with firmware version prior to V5.1.0.

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability may allow attackers to perform administrative operations over the network without authentication.

  • CVSS V3 rated as Low - 0 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-13-274-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591122

    Software Advisories
    Advisory ID Software Component Link
    ICSA-13-274-01 URL Logo www.cisa.gov/uscert/ics/advisories/ICSA-13-274-01
    ssa-176087 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-176087.pdf