CVE-2022-46144
published 2022-12-13CVE-2022-46144: A vulnerability has been identified in SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (All versions = V2.3 = V2.3 = V2.3 = V2.3 = V2.3 = V2.3 < V3.0), SCALANCE…
PriorityP333medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.87%
55.1th percentile
A vulnerability has been identified in SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (All versions = V2.3 = V2.3 = V2.3 = V2.3 = V2.3 = V2.3 < V3.0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) (All versions < V2.0.0), SCALANCE WAM766-1 (6GK5766-1GE00-7DA0) (All versions < V2.0.0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0) (All versions < V2.0.0), SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0) (All versions < V2.0.0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0) (All versions < V2.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0) (All versions < V2.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0) (All versions < V2.0.0), SCALANCE WUM766-1 (6GK5766-1GE00-3DA0) (All versions < V2.0.0), SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0) (All versions < V2.0.0). Affected devices do not properly process CLI commands after a user forcefully quitted the SSH connection. This could allow an authenticated attacker to make the CLI via SSH or serial interface irresponsive.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | 6gk5622-2gs00-2ac2_firmware | < 2.3 | 2.3 |
| siemens | 6gk5622-2gs00-2ac2_firmware | >= 2.3 < 3.0 | 3.0 |
| siemens | 6gk5626-2gs00-2ac2_firmware | < 2.3 | 2.3 |
| siemens | 6gk5626-2gs00-2ac2_firmware | >= 2.3 < 3.0 | 3.0 |
| siemens | 6gk5632-2gs00-2ac2_firmware | < 2.3 | 2.3 |
| siemens | 6gk5632-2gs00-2ac2_firmware | >= 2.3 < 3.0 | 3.0 |
| siemens | 6gk5636-2gs00-2ac2_firmware | < 2.3 | 2.3 |
| siemens | 6gk5636-2gs00-2ac2_firmware | >= 2.3 < 3.0 | 3.0 |
| siemens | 6gk5642-2gs00-2ac2_firmware | < 2.3 | 2.3 |
| siemens | 6gk5642-2gs00-2ac2_firmware | >= 2.3 < 3.0 | 3.0 |
| siemens | 6gk5646-2gs00-2ac2_firmware | < 2.3 | 2.3 |
| siemens | 6gk5646-2gs00-2ac2_firmware | >= 2.3 < 3.0 | 3.0 |
| siemens | scalance_sc622-2c | < V2.3 | V2.3 |
| siemens | scalance_sc622-2c | >= V2.3 < V3.0 | V3.0 |
| siemens | scalance_sc626-2c | < V2.3 | V2.3 |
| siemens | scalance_sc626-2c | >= V2.3 < V3.0 | V3.0 |
| siemens | scalance_sc632-2c | < V2.3 | V2.3 |
| siemens | scalance_sc632-2c | >= V2.3 < V3.0 | V3.0 |
| siemens | scalance_sc636-2c | < V2.3 | V2.3 |
| siemens | scalance_sc636-2c | >= V2.3 < V3.0 | V3.0 |
| siemens | scalance_sc642-2c | < V2.3 | V2.3 |
| siemens | scalance_sc642-2c | >= V2.3 < V3.0 | V3.0 |
| siemens | scalance_sc646-2c | < V2.3 | V2.3 |
| siemens | scalance_sc646-2c | >= V2.3 < V3.0 | V3.0 |
| siemens | scalance_wam763-1 | < V2.0.0 | V2.0.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.07.1HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE W700
cisa_ics·2024-06-13
Siemens SCALANCE W700
ICS Advisory
##
Siemens SCALANCE W700
Release DateJune 13, 2024
Alert CodeICSA-24-165-12
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE W700 devices
- Vulnerabilities: Improper Control of a Resource Through its Lifetime, Acceptance of Extraneous Untrusted Data With
CISA ICS
Siemens Multiple Vulnerabilities in SCALANCE Products
cisa_ics·2022-12-15·CVSS 8.8
[HIGH] Siemens Multiple Vulnerabilities in SCALANCE Products
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Multiple Vulnerabilities in SCALANCE Products
Last RevisedDecember 15, 2022
Alert CodeICSA-22-349-04
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.6
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM and SCALANCE device
GHSA
GHSA-p939-r66p-8wwm: A vulnerability has been identified in SCALANCE SC622-2C (All versions = 2
ghsa_unreviewed·2022-12-13
CVE-2022-46144 [MEDIUM] CWE-664 GHSA-p939-r66p-8wwm: A vulnerability has been identified in SCALANCE SC622-2C (All versions = 2
A vulnerability has been identified in SCALANCE SC622-2C (All versions = 2.3 = 2.3 = 2.3 = 2.3 = 2.3 = 2.3 < V3.0). Affected devices do not properly process CLI commands after a user forcefully quitted the SSH connection. This could allow an authenticated attacker to make the CLI via SSH or serial interface irresponsive.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/html/ssa-413565.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-690517.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-413565.pdfhttps://cert-portal.siemens.com/productcert/html/ssa-413565.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-690517.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-413565.pdf
2022-12-13
Published