QID 591280

Date Published: 2023-01-13

QID 591280: Siemens SCALANCE X-200RNA Switch Devices Denial of Service (DoS) Multiple Vulnerabilities (ICSA-22-349-21, SSA-412672)

AFFECTED PRODUCTS
SCALANCE X204RNA (HSR) (6GK5204-0BA00-2MB2): All versions prior to V3.2.7
SCALANCE X204RNA (PRP) (6GK5204-0BA00-2KB2): All versions prior to V3.2.7
SCALANCE X204RNA EEC (HSR) (6GK5204-0BS00-2NA3): All versions prior to V3.2.7
SCALANCE X204RNA EEC (PRP) (6GK5204-0BS00-3LA3): All versions prior to V3.2.7
SCALANCE X204RNA EEC (PRP/HSR) (6GK5204-0BS00-3PA3): All versions prior to V3.2.7

QID Detection Logic:
This QID checks for the Vulnerable version of Siemens SCALANCE X-200RNA Switch Devices using passive scanning

Successful exploitation of these vulnerabilities could allow a denial-of-service condition or could lead to execution of arbitrary code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-22-349-21 or Siemens MITIGATIONS section SSA-412672 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-22-349-21 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-349-21
    SSA-412672 URL Logo cert-portal.siemens.com/productcert/html/ssa-412672.html