Improper access control in Siemens products - CVE-2022-46354

 

Improper access control in Siemens products - CVE-2022-46354

Published: December 16, 2022


Vulnerability identifier: #VU70393
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46354
CWE-ID: CWE-284
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in the webserver. A remote attacker on the local network can bypass implemented security restrictions and extract confidential session information under certain circumstances.


Affected software

SCALANCE X204RNA (HSR)
SCALANCE X204RNA (PRP)
SCALANCE X204RNA EEC (HSR)
SCALANCE X204RNA EEC (PRP)
SCALANCE X204RNA EEC (PRP/HSR)

How to mitigate CVE-2022-46354

Install updates from vendor's website.

SCALANCE X204RNA (HSR) - update to 3.2.7
SCALANCE X204RNA (PRP) - update to 3.2.7
SCALANCE X204RNA EEC (HSR) - update to 3.2.7
SCALANCE X204RNA EEC (PRP) - update to 3.2.7
SCALANCE X204RNA EEC (PRP/HSR) - update to 3.2.7

External References

Related Security Bulletins