CVE-2023-29054
Published Apr 11, 2023
Last updated 2 years ago
Overview
- Description
- A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT PRO (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2P IRT (All versions < V5.5.2), SCALANCE X202-2P IRT PRO (All versions < V5.5.2), SCALANCE X204IRT (All versions < V5.5.2), SCALANCE X204IRT (All versions < V5.5.2), SCALANCE X204IRT PRO (All versions < V5.5.2), SCALANCE XF201-3P IRT (All versions < V5.5.2), SCALANCE XF202-2P IRT (All versions < V5.5.2), SCALANCE XF204-2BA IRT (All versions < V5.5.2), SCALANCE XF204IRT (All versions < V5.5.2), SIPLUS NET SCALANCE X202-2P IRT (All versions < V5.5.2). The SSH server on affected devices is configured to offer weak ciphers by default. This could allow an unauthorized attacker in a man-in-the-middle position to read and modify any data passed over the connection between legitimate clients and the affected device.
- Source
- productcert@siemens.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.4
- Impact score
- 5.2
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity
- HIGH
Weaknesses
- productcert@siemens.com
- CWE-326
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x200-4p_irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "22AB35F0-99D8-4E09-B76B-5CEA0F2916D5", "versionEndExcluding": "5.5.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x200-4p_irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8B9CBC72-92D9-4B3A-884F-33124C457016" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x201-3p_irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "04EC0D48-53B2-42B4-B008-976664B31161", "versionEndExcluding": "5.5.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x201-3p_irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3268CF75-6DAB-416A-B19B-2A8F95C268CF" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x201-3p_irt_pro_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "72870433-6CC1-4574-B8E4-A456A348A6C1", "versionEndExcluding": "5.5.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x201-3p_irt_pro:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "492E8AC1-338B-4AC3-90C7-1FADCD4528C4" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x202-2irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D2177B7B-099A-40E5-BA2F-C7CB4DAA7EEA", "versionEndExcluding": "5.5.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x202-2irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A8B1D979-038F-42F4-AB7D-E0664D051B4E" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x202-2irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D2177B7B-099A-40E5-BA2F-C7CB4DAA7EEA", "versionEndExcluding": "5.5.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x202-2irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A8B1D979-038F-42F4-AB7D-E0664D051B4E" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x202-2p_irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "799E0913-E071-4136-96F0-27FF40FD7D22", "versionEndExcluding": "5.5.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x202-2p_irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CEB62730-E759-455A-A308-F9DB084B35B5" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x202-2p_irt_pro_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C3C17B6E-FE1B-4A56-89C2-6B1060B09139", "versionEndExcluding": "5.5.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x202-2p_irt_pro:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F4726901-34BF-4F70-80A6-71648A4A29FB" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x204irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D66C306-B0E0-4000-AD3C-80E20E538726", "versionEndExcluding": "5.5.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x204irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6716DCDE-BD3F-4BA2-A66A-A0C14C6A3C15" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x204irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D66C306-B0E0-4000-AD3C-80E20E538726", "versionEndExcluding": "5.5.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x204irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6716DCDE-BD3F-4BA2-A66A-A0C14C6A3C15" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x204irt_pro_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F812AD70-3AEB-4F35-B8B1-C0D76AE1C1D8", "versionEndExcluding": "5.5.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x204irt_pro:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "1769DB7A-F832-4D89-8ED0-8677F750059D" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xf201-3p_irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6835BD4D-2EE0-4484-A5F1-6B4C472F2C57", "versionEndExcluding": "5.5.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xf201-3p_irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "41614C70-97B4-44C8-A441-530A413A26F9" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xf202-2p_irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6E5244AF-43E2-4A2B-AD60-4F54394D636D", "versionEndExcluding": "5.5.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xf202-2p_irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6751FB7D-C72C-4321-B535-5880FE696FC3" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xf204-2ba_irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "71460FAA-58B5-44BD-8C3F-85919D4ADDEB", "versionEndExcluding": "5.5.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xf204-2ba_irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "99E6AFAA-B903-47BB-B0F3-7650B039C0FB" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xf204irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5917B7D6-894F-487D-8CD5-12542CC6693A", "versionEndExcluding": "5.5.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xf204irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "57E5489B-277A-4D02-B4AB-4DB65969EED2" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:siplus_net_scalance_x202-2p_irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0D2E73C-B605-4DD3-AD04-85CF154E95A1", "versionEndExcluding": "5.5.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:siplus_net_scalance_x202-2p_irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "1C3504F0-D0F4-4106-824E-A87E46DADC3B" } ], "operator": "OR" } ], "operator": "AND" } ]