QID 591286

Date Published: 2023-01-13

QID 591286: Siemens SCALANCE DROWN (Decrypting Rivest Shamir Adleman (RSA) with Obsolete and Weakened eNcryption) Vulnerability (ICSA-16-103-03C, SSA-623229)

AFFECTED PRODUCTS
SCALANCE X300 family: All versions prior to V4.1.0,
SCALANCE X414: All versions prior to V3.10.2,
SCALANCE X200 IRT family: All versions prior to V5.3.0,
SCALANCE X200 RNA family: All versions prior to V3.2.5,
SCALANCE X200 family: All versions prior to V5.2.2,

QID Detection Logic:
This QID checks for the Vulnerable version of Omron NJ/NX-series Machine Automation Controllers using passive scanning

An attacker in a privileged network position could use this vulnerability to intercept transport layer security sessions.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-16-103-03 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591286

    Software Advisories
    Advisory ID Software Component Link
    ICSA-16-103-03 URL Logo www.cisa.gov/uscert/ics/advisories/ICSA-16-103-03