CVE-2022-31766
published 2022-10-11CVE-2022-31766: A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions = V1.1.0 = V1.1.0 = V1.1.0 = V1.1.0 = V1.1.0 = V1.1.0 =…
PriorityP348high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
EPSS
1.04%
60.3th percentile
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions = V1.1.0 = V1.1.0 = V1.1.0 = V1.1.0 = V1.1.0 = V1.1.0 = V1.1.0 = V1.1.0 = V1.1.0 < V3.0.0). Affected devices with TCP Event service enabled do not properly handle malformed packets.
This could allow an unauthenticated remote attacker to cause a denial of service condition and reboot the device thus possibly affecting other network resources.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | ruggedcom_rm1224_firmware | < 7.1.2 | 7.1.2 |
| siemens | ruggedcom_rm1224_lte_eu | < V7.1.2 | V7.1.2 |
| siemens | ruggedcom_rm1224_lte_nam | < V7.1.2 | V7.1.2 |
| siemens | scalance_m804pb | < V7.1.2 | V7.1.2 |
| siemens | scalance_m804pb_firmware | < 7.1.2 | 7.1.2 |
| siemens | scalance_m812-1_adsl-router | < V7.1.2 | V7.1.2 |
| siemens | scalance_m812-1_firmware | < 7.1.2 | 7.1.2 |
| siemens | scalance_m816-1_adsl-router | < V7.1.2 | V7.1.2 |
| siemens | scalance_m816-1_firmware | < 7.1.2 | 7.1.2 |
| siemens | scalance_m826-2_firmware | < 7.1.2 | 7.1.2 |
| siemens | scalance_m826-2_shdsl-router | < V7.1.2 | V7.1.2 |
| siemens | scalance_m874-2 | < V7.1.2 | V7.1.2 |
| siemens | scalance_m874-2_firmware | < 7.1.2 | 7.1.2 |
| siemens | scalance_m874-3 | < V7.1.2 | V7.1.2 |
| siemens | scalance_m874-3_firmware | < 7.1.2 | 7.1.2 |
| siemens | scalance_m876-3 | < V7.1.2 | V7.1.2 |
| siemens | scalance_m876-3_firmware | < 7.1.2 | 7.1.2 |
| siemens | scalance_m876-4 | < V7.1.2 | V7.1.2 |
| siemens | scalance_m876-4_firmware | < 7.1.2 | 7.1.2 |
| siemens | scalance_mum853-1 | < V7.1.2 | V7.1.2 |
| siemens | scalance_mum853-1_firmware | < 7.1.2 | 7.1.2 |
| siemens | scalance_mum856-1 | < V7.1.2 | V7.1.2 |
| siemens | scalance_mum856-1_firmware | < 7.1.2 | 7.1.2 |
| siemens | scalance_s615_eec_lan-router | < V7.1.2 | V7.1.2 |
| siemens | scalance_s615_firmware | < 7.1.2 | 7.1.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens TCP Event Service of SCALANCE And RUGGEDCOM Devices
cisa_ics·2023-01-13
Siemens TCP Event Service of SCALANCE And RUGGEDCOM Devices
ICS Advisory
##
Siemens TCP Event Service of SCALANCE And RUGGEDCOM Devices
Last RevisedJanuary 13, 2023
Alert CodeICSA-22-286-08
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.6
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE, RUGGEDCOM
- Vulnerability: Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to render the device
GHSA
GHSA-gh7w-58g5-rmwx: A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (All versions = V1
ghsa_unreviewed·2022-10-11
CVE-2022-31766 [HIGH] CWE-20 GHSA-gh7w-58g5-rmwx: A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (All versions = V1
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (All versions = V1.1.0), SCALANCE WAM766-1 (All versions >= V1.1.0), SCALANCE WAM766-1 (All versions >= V1.1.0), SCALANCE WAM766-1 6GHz (All versions >= V1.1.0), SCALANCE WAM766-1 EEC (All versions >= V1.1.0), SCALANCE WAM766-1 EEC (All versions >= V1.1.0), SCALANCE WAM766-1 EEC 6GHz (All versions >= V1.1.0), SCALANCE WUM763-1 (All versions >= V1.1.0), SCALANCE WUM763-1 (All versions >= V1.1.0), SCALANCE WUM766-1 (All versions >= V1.1.0), SCALANCE WUM766-1 (All versions >= V1.1.0), SCALANCE WUM766-1 6GHz (All versions >= V1.1.0). Affected devices with TCP Event service enabled do not properly handle malformed packets. This could allow an unauthenticated remote attacker to cause a denial of service and reboot the device thus
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-11
Published