CVE-2022-25755
Published Apr 12, 2022
Last updated a year ago
Overview
- Description
- A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 230V, coated), SCALANCE X302-7 EEC (2x 24V), SCALANCE X302-7 EEC (2x 24V, coated), SCALANCE X304-2FE, SCALANCE X306-1LD FE, SCALANCE X307-2 EEC (230V), SCALANCE X307-2 EEC (230V, coated), SCALANCE X307-2 EEC (24V), SCALANCE X307-2 EEC (24V, coated), SCALANCE X307-2 EEC (2x 230V), SCALANCE X307-2 EEC (2x 230V, coated), SCALANCE X307-2 EEC (2x 24V), SCALANCE X307-2 EEC (2x 24V, coated), SCALANCE X307-3, SCALANCE X307-3, SCALANCE X307-3LD, SCALANCE X307-3LD, SCALANCE X308-2, SCALANCE X308-2, SCALANCE X308-2LD, SCALANCE X308-2LD, SCALANCE X308-2LH, SCALANCE X308-2LH, SCALANCE X308-2LH+, SCALANCE X308-2LH+, SCALANCE X308-2M, SCALANCE X308-2M, SCALANCE X308-2M PoE, SCALANCE X308-2M PoE, SCALANCE X308-2M TS, SCALANCE X308-2M TS, SCALANCE X310, SCALANCE X310, SCALANCE X310FE, SCALANCE X310FE, SCALANCE X320-1 FE, SCALANCE X320-1-2LD FE, SCALANCE X408-2, SCALANCE XR324-12M (230V, ports on front), SCALANCE XR324-12M (230V, ports on front), SCALANCE XR324-12M (230V, ports on rear), SCALANCE XR324-12M (230V, ports on rear), SCALANCE XR324-12M (24V, ports on front), SCALANCE XR324-12M (24V, ports on front), SCALANCE XR324-12M (24V, ports on rear), SCALANCE XR324-12M (24V, ports on rear), SCALANCE XR324-12M TS (24V), SCALANCE XR324-12M TS (24V), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (24V, ports on front), SCALANCE XR324-4M EEC (24V, ports on front), SCALANCE XR324-4M EEC (24V, ports on rear), SCALANCE XR324-4M EEC (24V, ports on rear), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (2x 24V, ports on front), SCALANCE XR324-4M EEC (2x 24V, ports on front), SCALANCE XR324-4M EEC (2x 24V, ports on rear), SCALANCE XR324-4M EEC (2x 24V, ports on rear), SCALANCE XR324-4M PoE (230V, ports on front), SCALANCE XR324-4M PoE (230V, ports on rear), SCALANCE XR324-4M PoE (24V, ports on front), SCALANCE XR324-4M PoE (24V, ports on rear), SCALANCE XR324-4M PoE TS (24V, ports on front), SIPLUS NET SCALANCE X308-2. The webserver of an affected device is missing specific security headers. This could allow an remote attacker to extract confidential session information under certain circumstances.
- Source
- productcert@siemens.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
- productcert@siemens.com
- CWE-284
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x302-7eec_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7FB6F150-2662-44AE-8DC1-0B0A426E8352", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x302-7eec:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C8E97B3B-1808-45D2-97B7-CF31CA6E7A60" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x304-2fe_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E9F4071F-1AE2-4FAD-A8CB-1619552101A3", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x304-2fe:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0087A1C6-AA76-4FD6-BAA1-D3190D2A0116" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x306-1ldfe_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4B78CFDF-1B15-4A4B-99D4-8CC5E1867BD1", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x306-1ldfe:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "880CF41B-B25D-4744-8E8B-C4B131932B1B" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x307-2eec_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CCB1094D-3F8A-4331-ABB9-46B73F7E008F", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x307-2eec:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "804EE08B-75A1-4CF6-9C30-8CF0CDC39658" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x307-3_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EE21803A-A5CA-482A-ABD2-C9A547831BF6", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x307-3:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "55EF0738-C9EF-4E4B-A7E7-ECC1B5F0678A" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x307-3ld_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EEBFBB10-35E0-46BB-A937-E9A933C4D5BC", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x307-3ld:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7737F0C2-43FC-4330-88F2-9B08BA5B35D7" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x308-2_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4C91F6DD-A74C-4310-88AB-63A39D0208BE", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x308-2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6CCED3E4-38EF-4645-B25C-4F2C3D4E091C" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x308-2ld_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B5513D8-59DD-4EE1-B2E8-F800D1DA7BC5", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x308-2ld:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FE1909FA-C8C6-46BE-83C6-2635D36FE69B" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x308-2lh_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A11DE626-D744-49A7-93C4-FE2C2AF5245F", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x308-2lh:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6DDBD94D-5312-4A54-AF76-D9DF791C0292" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x308-2lh\\+_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DC259CD1-5C79-4491-B375-7A69116F2747", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x308-2lh\\+:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "85153EED-C677-495D-A6BB-72365DE1ED3F" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x308-2m_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "79918934-7B0B-4032-972E-2347CD33029D", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x308-2m:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AC54911E-C432-48FA-9551-9644422FFE14" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x308-2m_poe_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00FBD442-84AA-48F3-8AD1-5767FFB2FC3F" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x308-2m_poe:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3E22C57C-2BD6-4C39-93D2-5D81A58EA6F0" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x308-2m_ts_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E72D4503-5AAE-4C6F-BAE9-FA51701191B1", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x308-2m_ts:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DFCCB68C-A58D-4543-A11F-721B01FFBBA4" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x310_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA2333C8-E9C7-43D8-9EAA-A88ECAAB4236", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x310:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7FE3716E-1C0A-4B72-809A-8318E5853FB1" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x310fe_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7EECD381-262F-4C47-90E1-7B44092C74BD", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x310fe:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8FB34E83-83A3-45C3-B040-D8910971D439" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x320-1fe_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "36C40232-5696-44CC-B38F-5331A745C760", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x320-1fe:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CC54880F-CBF4-4772-A4FB-B07D97287D44" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x320-1-2ldfe_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2F1969E4-CFD6-4AC7-956E-374967F5C406", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x320-1-2ldfe:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B2D400F5-AD80-4536-A99D-793E1560757B" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x408-2_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3ACB931D-C484-42F4-9912-24B44FE97017", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x408-2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0C632B90-EB11-4A4C-8128-DABBE044B9AF" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xr324-4m_eec_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B1EFA152-D29B-4116-A3D2-ACF7A025E053", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xr324-4m_eec:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6F952542-6B79-4681-A236-15C188AAEB1E" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xr324-4m_poe_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "935CD21D-0471-4D1F-AF81-B1F996A9EFAB", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xr324-4m_poe:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "664D9C76-BC13-4874-939C-A8211DA33903" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xr324-4m_poe_ts_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E2C0F1FB-8B5E-448C-A304-FDDCB3DFCDD4", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xr324-4m_poe_ts:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4834A67B-7B0B-4F88-BBFB-25667FD68EC5" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xr324-12m_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3E0E1F54-D9EA-4AFB-80EF-0A585EC3C641", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xr324-12m:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "36C9AE74-4683-4ED0-A605-3A6B065C230E" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xr324-12m_ts_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DC03DF92-C7A1-4232-AFDF-04B2B50666DB", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xr324-12m_ts:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4356417E-B4CB-45B0-B395-CE9D423FAB44" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:siplus_net_scalance_x308-2_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "25103533-B9BC-4553-B195-AF5CACAB713B", "versionEndExcluding": "4.1.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:siplus_net_scalance_x308-2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9C48C944-324B-4390-B9D1-3D0FC3DD5BFD" } ], "operator": "OR" } ], "operator": "AND" } ]