CVE-2012-1802
published 2012-04-18CVE-2012-1802: Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before…
PriorityP344high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
6.12%
92.6th percentile
Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before 3.7.2, XR-300 before 3.7.2, and X-300 before 3.7.2 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a malformed URL.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | scalance_x-300_firmware | <= 3.7.0 | — |
| siemens | scalance_x-300_firmware | — | — |
| siemens | scalance_x-300_firmware | — | — |
| siemens | scalance_x-300_firmware | — | — |
| siemens | scalance_x-300_firmware | — | — |
| siemens | scalance_x-300_firmware | — | — |
| siemens | scalance_x-300_firmware | — | — |
| siemens | scalance_x-300eec_firmware | <= 3.7.0 | — |
| siemens | scalance_x-300eec_firmware | — | — |
| siemens | scalance_x308-2m_firmware | <= 3.7.0 | — |
| siemens | scalance_x308-2m_firmware | — | — |
| siemens | scalance_x308-2m_firmware | — | — |
| siemens | scalance_x308-2m_firmware | — | — |
| siemens | scalance_x414-3e_firmware | <= 3.7.0 | — |
| siemens | scalance_x414-3e_firmware | — | — |
| siemens | scalance_x414-3e_firmware | — | — |
| siemens | scalance_x414-3e_firmware | — | — |
| siemens | scalance_x414-3e_firmware | — | — |
| siemens | scalance_x414-3e_firmware | — | — |
| siemens | scalance_x414-3e_firmware | — | — |
| siemens | scalance_x414-3e_firmware | — | — |
| siemens | scalance_x414-3e_firmware | — | — |
| siemens | scalance_x414-3e_firmware | — | — |
| siemens | scalance_xr-300_firmware | <= 3.7.0 | — |
| siemens | scalance_xr-300_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens Scalance X Buffer Overflow Vulnerability
cisa_ics·2013-05-08
Siemens Scalance X Buffer Overflow Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Scalance X Buffer Overflow Vulnerability
Last RevisedMay 08, 2013
Alert CodeICSA-12-102-04
## Overview
ICS-CERT has received a report from Siemens regarding a buffer overflow vulnerability in the web interface of the Scalance X Industrial Ethernet switch. This vulnerability was reported to Siemens by Jürgen Bilberger from Daimler TSS GmbH.
This vulnerability leaves the affected devices susceptible to a remote denial of service attack. Siemens has published a firmware update that addresses this vulnerability.
## Affected Products
The following Scalance X products affec
GHSA
GHSA-45r8-2cqp-rwrj: Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3
ghsa_unreviewed·2022-05-17
CVE-2012-1802 [HIGH] CWE-119 GHSA-45r8-2cqp-rwrj: Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3
Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before 3.7.2, XR-300 before 3.7.2, and X-300 before 3.7.2 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a malformed URL.
No detection rules found.
No public exploits indexed.
http://osvdb.org/81032http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-130874.pdfhttp://www.us-cert.gov/control_systems/pdf/ICSA-12-102-04.pdfhttp://osvdb.org/81032http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-130874.pdfhttp://www.us-cert.gov/control_systems/pdf/ICSA-12-102-04.pdf
2012-04-18
Published