CVE-2022-31765
published 2022-10-11CVE-2022-31765: Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their…
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.90%
55.9th percentile
Affected devices do not properly authorize the change password function of the web interface.
This could allow low privileged users to escalate their privileges.
Affected
109 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | 6gk5804-0ap00-2aa2_firmware | < 7.1.2 | 7.1.2 |
| siemens | 6gk5812-1aa00-2aa2_firmware | < 7.1.2 | 7.1.2 |
| siemens | 6gk5812-1ba00-2aa2_firmware | < 7.1.2 | 7.1.2 |
| siemens | 6gk5816-1aa00-2aa2_firmware | < 7.1.2 | 7.1.2 |
| siemens | 6gk5816-1ba00-2aa2_firmware | < 7.1.2 | 7.1.2 |
| siemens | 6gk5826-2ab00-2ab2_firmware | < 7.1.2 | 7.1.2 |
| siemens | 6gk5853-2ea00-2da1_firmware | < 7.1.2 | 7.1.2 |
| siemens | 6gk5856-2ea00-3aa1_firmware | < 7.1.2 | 7.1.2 |
| siemens | 6gk5856-2ea00-3da1_firmware | < 7.1.2 | 7.1.2 |
| siemens | 6gk5874-2aa00-2aa2_firmware | < 7.1.2 | 7.1.2 |
| siemens | 6gk5874-3aa00-2aa2_firmware | < 7.1.2 | 7.1.2 |
| siemens | 6gk5876-3aa02-2ba2_firmware | < 7.1.2 | 7.1.2 |
| siemens | 6gk5876-3aa02-2ea2_firmware | < 7.1.2 | 7.1.2 |
| siemens | 6gk5876-4aa00-2ba2_firmware | < 7.1.2 | 7.1.2 |
| siemens | 6gk5876-4aa00-2da2_firmware | < 7.1.2 | 7.1.2 |
| siemens | 6gk6108-4am00-2ba2_firmware | < 7.1.2 | 7.1.2 |
| siemens | 6gk6108-4am00-2da2_firmware | < 7.1.2 | 7.1.2 |
| siemens | ruggedcom_rm1224_lte_eu | < V7.1.2 | V7.1.2 |
| siemens | ruggedcom_rm1224_lte_nam | < V7.1.2 | V7.1.2 |
| siemens | scalance_m804pb | < V7.1.2 | V7.1.2 |
| siemens | scalance_m812-1_adsl-router | < V7.1.2 | V7.1.2 |
| siemens | scalance_m816-1_adsl-router | < V7.1.2 | V7.1.2 |
| siemens | scalance_m826-2_shdsl-router | < V7.1.2 | V7.1.2 |
| siemens | scalance_m874-2 | < V7.1.2 | V7.1.2 |
| siemens | scalance_m874-3 | < V7.1.2 | V7.1.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-33vv-h74c-xmw5: Affected devices do not properly authorize the change password function of the web interface
ghsa_unreviewed·2022-10-11
CVE-2022-31765 [HIGH] CWE-862 GHSA-33vv-h74c-xmw5: Affected devices do not properly authorize the change password function of the web interface
Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges.
CISA ICS
Siemens SCALANCE and RUGGEDCOM Products (Update B)
cisa_ics·2023-01-13
Siemens SCALANCE and RUGGEDCOM Products (Update B)
ICS Advisory
##
Siemens SCALANCE and RUGGEDCOM Products (Update B)
Last RevisedJanuary 13, 2023
Alert CodeICSA-22-286-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Multiple SCALANCE and RUGGEDCOM products
- Vulnerability: Missing Authorization
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-22-286-11 Siemens SCALANCE a
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-11
Published