CVE-2019-6567
published 2019-06-12CVE-2019-6567: A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch family (incl…
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.30%
22.0th percentile
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.3), SCALANCE X-414-3E (All versions). The affected devices store passwords in a recoverable format. An attacker may extract and recover device passwords from the device configuration. Successful exploitation requires access to a device configuration backup and impacts confidentiality of the stored passwords.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| siemens | scalance_x-200_firmware | < 5.2.4 | 5.2.4 |
| siemens | scalance_x-200_switch_family | — | — |
| siemens | scalance_x-200irt_switch_family | — | — |
| siemens | scalance_x-300_switch_family | — | — |
| siemens | scalance_x-414-3e | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2020-6566
vendor_chrome·2020-08-25·CVSS 6.5
CVE-2020-6566 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-6566
Stable Channel Update for Desktop
CVE-2020-6566: Insufficient policy enforcement in media. Reported by Jun Kokatsu, Microsoft Browser Vulnerability Research on 2020-03-27 [$500][ 937179 ] Low CVE-2020-6567: Insufficient validation of untrusted input in command line handling
Reported by Joshua Graham of TSS on 2019-03-01 [$500][ 1092451 ] Low CVE-2020-6568: Insufficient policy enforcement in intent handling
Severity: medium
CISA ICS
Siemens SCALANCE X (Update B)
cisa_ics·2020-01-14·CVSS 5.5
[MEDIUM] Siemens SCALANCE X (Update B)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE X (Update B)
Last RevisedFebruary 09, 2021
Alert CodeICSA-19-162-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.1
- ATTENTION: Low skill level to exploit
- Vendor: Siemens
- Equipment: SCALANCE X Switches
- Vulnerability: Storing Passwords in a Recoverable Format
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-19-162-04 Siemens SCALANCE X (Update A) that was published January 14, 2020, to the ICS webpage on us-cert.cisa.gov.
## 3. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacke
GHSA
GHSA-9mw7-3797-xp7x: A vulnerability has been identified in SCALANCE X-200 (All Versions < V5
ghsa_unreviewed·2022-05-24
CVE-2019-6567 [MEDIUM] CWE-522 GHSA-9mw7-3797-xp7x: A vulnerability has been identified in SCALANCE X-200 (All Versions < V5
A vulnerability has been identified in SCALANCE X-200 (All Versions < V5.2.4), SCALANCE X-200IRT (All versions), SCALANCE X-300 (All versions), SCALANCE X-414-3E (All versions). The affected devices store passwords in a recoverable format. An attacker may extract and recover device passwords from the device configuration. Successful exploitation requires access to a device configuration backup and impacts confidentiality of the stored passwords. At the time of advisory publication no public exploitation of this security vulnerability was known.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-06-12
Published