Improper Neutralization of Special Elements in Output Used by a Downstream Component in Siemens products - CVE-2022-36323
Published: August 10, 2022
Vulnerability identifier: #VU66368
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-36323
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote administrator can inject arbitrary code or spawn a system root shell.
Affected software
SCALANCE M-800 / S615
SCALANCE W-700 (IEEE 802.11ax)
SCALANCE W-700 (IEEE 802.11n)
SCALANCE W-1700 (IEEE 802.11ac)
SCALANCE S615
SCALANCE XB-200
SCALANCE XC-200
SCALANCE XF-200BA
SCALANCE XM-400
SCALANCE XP-200
SCALANCE XR-300WG
SCALANCE XR-500
SCALANCE SC-600
SCALANCE WAM763-1
SCALANCE WAM766-1
SCALANCE WAM766-1 EEC
SCALANCE WUM763-1
SCALANCE WUM766-1
SCALANCE M876-3 (EVDO)
SCALANCE S615 EEC
SCALANCE MUM856-1 (RoW)
SCALANCE MUM856-1 (EU)
SCALANCE MUM853-1 (EU)
SCALANCE M876-4 (NAM)
SCALANCE M876-4 (EU)
SCALANCE M876-4
SCALANCE M876-3 (ROK)
RUGGEDCOM RM1224 LTE(4G) EU
SCALANCE M874-3
SCALANCE M874-2
SCALANCE M826-2 SHDSL-Router
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M804PB
RUGGEDCOM RM1224 LTE(4G) NAM
SCALANCE W-700 (IEEE 802.11ax)
SCALANCE W-700 (IEEE 802.11n)
SCALANCE W-1700 (IEEE 802.11ac)
SCALANCE S615
SCALANCE XB-200
SCALANCE XC-200
SCALANCE XF-200BA
SCALANCE XM-400
SCALANCE XP-200
SCALANCE XR-300WG
SCALANCE XR-500
SCALANCE SC-600
SCALANCE WAM763-1
SCALANCE WAM766-1
SCALANCE WAM766-1 EEC
SCALANCE WUM763-1
SCALANCE WUM766-1
SCALANCE M876-3 (EVDO)
SCALANCE S615 EEC
SCALANCE MUM856-1 (RoW)
SCALANCE MUM856-1 (EU)
SCALANCE MUM853-1 (EU)
SCALANCE M876-4 (NAM)
SCALANCE M876-4 (EU)
SCALANCE M876-4
SCALANCE M876-3 (ROK)
RUGGEDCOM RM1224 LTE(4G) EU
SCALANCE M874-3
SCALANCE M874-2
SCALANCE M826-2 SHDSL-Router
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M804PB
RUGGEDCOM RM1224 LTE(4G) NAM
How to mitigate CVE-2022-36323
Install updates from vendor's website.
SCALANCE SC-600 - update to 2.3.1
SCALANCE M876-3 (EVDO) - update to 8.0
SCALANCE S615 EEC - update to 8.0
SCALANCE S615 - update to 8.0
SCALANCE MUM856-1 (RoW) - update to 8.0
SCALANCE MUM856-1 (EU) - update to 8.0
SCALANCE MUM853-1 (EU) - update to 8.0
SCALANCE M876-4 (NAM) - update to 8.0
SCALANCE M876-4 (EU) - update to 8.0
SCALANCE M876-4 - update to 8.0
SCALANCE M876-3 (ROK) - update to 8.0
RUGGEDCOM RM1224 LTE(4G) EU - update to 8.0
SCALANCE M874-3 - update to 8.0
SCALANCE M874-2 - update to 8.0
SCALANCE M826-2 SHDSL-Router - update to 8.0
SCALANCE M816-1 ADSL-Router (Annex B) - update to 8.0
SCALANCE M816-1 ADSL-Router (Annex A) - update to 8.0
SCALANCE M812-1 ADSL-Router (Annex B) - update to 8.0
SCALANCE M812-1 ADSL-Router (Annex A) - update to 8.0
SCALANCE M804PB - update to 8.0
RUGGEDCOM RM1224 LTE(4G) NAM - update to 8.0
SCALANCE M876-3 (EVDO) - update to 8.0
SCALANCE S615 EEC - update to 8.0
SCALANCE S615 - update to 8.0
SCALANCE MUM856-1 (RoW) - update to 8.0
SCALANCE MUM856-1 (EU) - update to 8.0
SCALANCE MUM853-1 (EU) - update to 8.0
SCALANCE M876-4 (NAM) - update to 8.0
SCALANCE M876-4 (EU) - update to 8.0
SCALANCE M876-4 - update to 8.0
SCALANCE M876-3 (ROK) - update to 8.0
RUGGEDCOM RM1224 LTE(4G) EU - update to 8.0
SCALANCE M874-3 - update to 8.0
SCALANCE M874-2 - update to 8.0
SCALANCE M826-2 SHDSL-Router - update to 8.0
SCALANCE M816-1 ADSL-Router (Annex B) - update to 8.0
SCALANCE M816-1 ADSL-Router (Annex A) - update to 8.0
SCALANCE M812-1 ADSL-Router (Annex B) - update to 8.0
SCALANCE M812-1 ADSL-Router (Annex A) - update to 8.0
SCALANCE M804PB - update to 8.0
RUGGEDCOM RM1224 LTE(4G) NAM - update to 8.0