CVE-2022-46354Improper Access Control in Siemens Scalance X204rna

Severity
5.3MEDIUMNVD
EPSS
0.3%
top 45.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 13

Description

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of an affected device is missing specific security headers. This could allow an remote attacker to extract confidential session information under certain circumstances.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages7 packages

CVEListV5siemens/scalance_x204rnaAll versions < V3.2.7
CVEListV5siemens/scalance_x204rna_eecAll versions < V3.2.7

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9vcg-jgpf-m557: A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V32022-12-13
CVEList
CVE-2022-46354: A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V32022-12-13

💥Exploits & PoCs

1
Exploit-DB
Thinfinity VirtualUI 2.5.26.2 - Information Disclosure2022-02-21
CVE-2022-46354 — Improper Access Control in Siemens | cvebase