Information disclosure in Siemens products - CVE-2022-46355

 

Information disclosure in Siemens products - CVE-2022-46355

Published: December 16, 2022


Vulnerability identifier: #VU70394
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46355
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application in the HTTP Referer. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

SCALANCE X204RNA (HSR)
SCALANCE X204RNA (PRP)
SCALANCE X204RNA EEC (HSR)
SCALANCE X204RNA EEC (PRP)
SCALANCE X204RNA EEC (PRP/HSR)

How to mitigate CVE-2022-46355

Install updates from vendor's website.

SCALANCE X204RNA (HSR) - update to 3.2.7
SCALANCE X204RNA (PRP) - update to 3.2.7
SCALANCE X204RNA EEC (HSR) - update to 3.2.7
SCALANCE X204RNA EEC (PRP) - update to 3.2.7
SCALANCE X204RNA EEC (PRP/HSR) - update to 3.2.7

External References

Related Security Bulletins