QID 591371

Date Published: 2023-04-03

QID 591371: Siemens SCALANCE X200 IRT Improper Input Validation Vulnerability (ICSA-23-047-02, SSA-617755)

AFFECTED PRODUCTS
SCALANCE X200-4P IRT (6GK5200-4AH00-2BA3): All versions prior to V5.5.0
SCALANCE X201-3P IRT (6GK5201-3BH00-2BA3): All versions prior to V5.5.0
SCALANCE X201-3P IRT PRO (6GK5201-3JR00-2BA6): All versions prior to V5.5.0
SCALANCE X202-2IRT (6GK5202-2BB00-2BA3): All versions prior to V5.5.0
SCALANCE X202-2P IRT (6GK5202-2BH00-2BA3): All versions prior to V5.5.0
SCALANCE X202-2P IRT PRO (6GK5202-2JR00-2BA6): All versions prior to V5.5.0
SCALANCE X204IRT (6GK5204-0BA00-2BA3): All versions prior to V5.5.0
SCALANCE X204IRT PRO (6GK5204-0JA00-2BA6): All versions prior to V5.5.0
SCALANCE XF201-3P IRT (6GK5201-3BH00-2BD2): All versions prior to V5.5.0
SCALANCE XF202-2P IRT (6GK5202-2BH00-2BD2): All versions prior to V5.5.0
SCALANCE XF204-2BA IRT (6GK5204-2AA00-2BD2): All versions prior to V5.5.0
SCALANCE XF204IRT (6GK5204-0BA00-2BF2): All versions prior to V5.5.0
SIPLUS NET SCALANCE X202-2P IRT (6AG1202-2BH00-2BA3): All versions prior to V5.5.0

QID Detection Logic:
This QID checks for the Vulnerable version of Ovarro TBox using passive scanning.

Successful exploitation of this vulnerability could allow remote attackers to cause a denial-of-service condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ssa-617755 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591371

    Software Advisories
    Advisory ID Software Component Link
    ssa-617755 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-617755.pdf