CVE Feed

    Dashboard / CVE / CVE-2022-25751

    CVE-2022-25751

    A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 230V, coated), SCALANCE X302-7 EEC (2x 24V), SCALANCE X302-7 EEC (2x 24V, coated), SCALANCE X304-2FE, SCALANCE X306-1LD FE, SCALANCE X307-2 EEC (230V), SCALANCE X307-2 EEC (230V, coated), SCALANCE X307-2 EEC (24V), SCALANCE X307-2 EEC (24V, coated), SCALANCE X307-2 EEC (2x 230V), SCALANCE X307-2 EEC (2x 230V, coated), SCALANCE X307-2 EEC (2x 24V), SCALANCE X307-2 EEC (2x 24V, coated), SCALANCE X307-3, SCALANCE X307-3, SCALANCE X307-3LD, SCALANCE X307-3LD, SCALANCE X308-2, SCALANCE X308-2, SCALANCE X308-2LD, SCALANCE X308-2LD, SCALANCE X308-2LH, SCALANCE X308-2LH, SCALANCE X308-2LH+, SCALANCE X308-2LH+, SCALANCE X308-2M, SCALANCE X308-2M, SCALANCE X308-2M PoE, SCALANCE X308-2M PoE, SCALANCE X308-2M TS, SCALANCE X308-2M TS, SCALANCE X310, SCALANCE X310, SCALANCE X310FE, SCALANCE X310FE, SCALANCE X320-1 FE, SCALANCE X320-1-2LD FE, SCALANCE X408-2, SCALANCE XR324-12M (230V, ports on front), SCALANCE XR324-12M (230V, ports on front), SCALANCE XR324-12M (230V, ports on rear), SCALANCE XR324-12M (230V, ports on rear), SCALANCE XR324-12M (24V, ports on front), SCALANCE XR324-12M (24V, ports on front), SCALANCE XR324-12M (24V, ports on rear), SCALANCE XR324-12M (24V, ports on rear), SCALANCE XR324-12M TS (24V), SCALANCE XR324-12M TS (24V), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (24V, ports on front), SCALANCE XR324-4M EEC (24V, ports on front), SCALANCE XR324-4M EEC (24V, ports on rear), SCALANCE XR324-4M EEC (24V, ports on rear), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (2x 24V, ports on front), SCALANCE XR324-4M EEC (2x 24V, ports on front), SCALANCE XR324-4M EEC (2x 24V, ports on rear), SCALANCE XR324-4M EEC (2x 24V, ports on rear), SCALANCE XR324-4M PoE (230V, ports on front), SCALANCE XR324-4M PoE (230V, ports on rear), SCALANCE XR324-4M PoE (24V, ports on front), SCALANCE XR324-4M PoE (24V, ports on rear), SCALANCE XR324-4M PoE TS (24V, ports on front), SIPLUS NET SCALANCE X308-2. Affected devices do not properly validate the HTTP headers of incoming requests. This could allow an unauthenticated remote attacker to crash affected devices.

    Published:Apr 12, 2022
    Last Modified:Nov 21, 2024
    EPS:Apr 12, 2022
    EPSS Score:0.03257
    CVSS Score:7.5

    Affected Products

    Vendor
    Siemens
    Product
    Scalance X302-7eec
    Vendor
    Siemens
    Product
    Scalance X302-7eec Firmware
    Vendor
    Siemens
    Product
    Scalance X304-2fe
    Vendor
    Siemens
    Product
    Scalance X304-2fe Firmware
    Vendor
    Siemens
    Product
    Scalance X306-1ldfe
    Vendor
    Siemens
    Product
    Scalance X306-1ldfe Firmware
    Vendor
    Siemens
    Product
    Scalance X307-2eec
    Vendor
    Siemens
    Product
    Scalance X307-2eec Firmware
    Vendor
    Siemens
    Product
    Scalance X307-3
    Vendor
    Siemens
    Product
    Scalance X307-3 Firmware
    Vendor
    Siemens
    Product
    Scalance X307-3ld
    Vendor
    Siemens
    Product
    Scalance X307-3ld Firmware
    Vendor
    Siemens
    Product
    Scalance X308-2
    Vendor
    Siemens
    Product
    Scalance X308-2 Firmware
    Vendor
    Siemens
    Product
    Scalance X308-2ld
    Vendor
    Siemens
    Product
    Scalance X308-2ld Firmware
    Vendor
    Siemens
    Product
    Scalance X308-2lh
    Vendor
    Siemens
    Product
    Scalance X308-2lh\+
    Vendor
    Siemens
    Product
    Scalance X308-2lh\+ Firmware
    Vendor
    Siemens
    Product
    Scalance X308-2lh Firmware
    Vendor
    Siemens
    Product
    Scalance X308-2m
    Vendor
    Siemens
    Product
    Scalance X308-2m Firmware
    Vendor
    Siemens
    Product
    Scalance X308-2m Poe
    Vendor
    Siemens
    Product
    Scalance X308-2m Poe Firmware
    Vendor
    Siemens
    Product
    Scalance X308-2m Ts
    Vendor
    Siemens
    Product
    Scalance X308-2m Ts Firmware
    Vendor
    Siemens
    Product
    Scalance X310
    Vendor
    Siemens
    Product
    Scalance X310 Firmware
    Vendor
    Siemens
    Product
    Scalance X310fe
    Vendor
    Siemens
    Product
    Scalance X310fe Firmware
    Vendor
    Siemens
    Product
    Scalance X320-1-2ldfe
    Vendor
    Siemens
    Product
    Scalance X320-1-2ldfe Firmware
    Vendor
    Siemens
    Product
    Scalance X320-1fe
    Vendor
    Siemens
    Product
    Scalance X320-1fe Firmware
    Vendor
    Siemens
    Product
    Scalance X408-2
    Vendor
    Siemens
    Product
    Scalance X408-2 Firmware
    Vendor
    Siemens
    Product
    Scalance Xr324-12m
    Vendor
    Siemens
    Product
    Scalance Xr324-12m Firmware
    Vendor
    Siemens
    Product
    Scalance Xr324-12m Ts
    Vendor
    Siemens
    Product
    Scalance Xr324-12m Ts Firmware
    Vendor
    Siemens
    Product
    Scalance Xr324-4m Eec
    Vendor
    Siemens
    Product
    Scalance Xr324-4m Eec Firmware
    Vendor
    Siemens
    Product
    Scalance Xr324-4m Poe
    Vendor
    Siemens
    Product
    Scalance Xr324-4m Poe Firmware
    Vendor
    Siemens
    Product
    Scalance Xr324-4m Poe Ts
    Vendor
    Siemens
    Product
    Scalance Xr324-4m Poe Ts Firmware
    Vendor
    Siemens
    Product
    Siplus Net Scalance X308-2
    Vendor
    Siemens
    Product
    Siplus Net Scalance X308-2 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High