QID 591266

Date Published: 2023-01-20

QID 591266: Siemens SCALANCE X-300/X408 Switch Family Denial of Service (DoS) Multiple Vulnerabilities (ICSA-15-020-01, SSA-321046)

AFFECTED PRODUCTS
SCALANCE X-300 switch family: All versions prior to V4.0
SCALANCE X408: All versions prior to V4.0

QID Detection Logic:
This QID checks for the Vulnerable version of Siemens SCALANCE X-300/X408 Switch Family using passive scanning

Exploitation of these vulnerabilities may cause the target device to reboot. No packets are forwarded to connected devices until the reboot is completed.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-15-020-01 or Siemens MITIGATIONS section SSA-321046 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591266

    Software Advisories
    Advisory ID Software Component Link
    ICSA-15-020-01 URL Logo www.cisa.gov/uscert/ics/advisories/ICSA-15-020-01
    SSA-321046 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-321046.pdf