CVE-2024-30190
published 2024-04-09CVE-2024-30190: A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12…
PriorityP421medium6.1CVSS 3.1
AVAACLPRLUIRSCCNINAH
EPSS
0.20%
9.5th percentile
A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0), SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0), SCALANCE W1788-2IA M12 (6GK5788-2HY01-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | scalance_w1748-1_m12 | < * | * |
| siemens | scalance_w1788-1_m12 | < * | * |
| siemens | scalance_w1788-2_eec_m12 | < * | * |
| siemens | scalance_w1788-2_m12 | < * | * |
| siemens | scalance_w1788-2ia_m12 | < * | * |
| siemens | scalance_w721-1_rj45 | < * | * |
| siemens | scalance_w722-1_rj45 | < * | * |
| siemens | scalance_w734-1_rj45 | < * | * |
| siemens | scalance_w738-1_m12 | < * | * |
| siemens | scalance_w748-1_m12 | < * | * |
| siemens | scalance_w748-1_rj45 | < * | * |
| siemens | scalance_w761-1_rj45 | < * | * |
| siemens | scalance_w774-1_m12_eec | < * | * |
| siemens | scalance_w774-1_rj45 | < * | * |
| siemens | scalance_w778-1_m12 | < * | * |
| siemens | scalance_w778-1_m12_eec | < * | * |
| siemens | scalance_w786-1_rj45 | < * | * |
| siemens | scalance_w786-2_rj45 | < * | * |
| siemens | scalance_w786-2_sfp | < * | * |
| siemens | scalance_w786-2ia_rj45 | < * | * |
| siemens | scalance_w788-1_m12 | < * | * |
| siemens | scalance_w788-1_rj45 | < * | * |
| siemens | scalance_w788-2_m12 | < * | * |
| siemens | scalance_w788-2_m12_eec | < * | * |
| siemens | scalance_w788-2_rj45 | < * | * |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET EXPLOIT Possible Microsoft Support Diagnostic Tool Exploitation Inbound (CVE-2022-30190)
suricata·2022-05-31·CVSS 7.8
CVE-2022-30190 [HIGH] ET EXPLOIT Possible Microsoft Support Diagnostic Tool Exploitation Inbound (CVE-2022-30190)
ET EXPLOIT Possible Microsoft Support Diagnostic Tool Exploitation Inbound (CVE-2022-30190)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Microsoft Support Diagnostic Tool Exploitation Inbound (CVE-2022-30190)"; flow:established,to_client; file.data; bsize:>4095; content:"location.href"; nocase; pcre:"/^\s*=\s*[\x22\x27]\s*ms-msdt\x3a/Ri"; content:"ms-msdt|3a|"; fast_pattern; nocase; reference:cve,2022-30190; classtype:attempted-user; sid:2036726; rev:3; metadata:attack_target Server, created_at 2022_05_31, cve CVE_2022_30190, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_03_08, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_techni
No public exploits indexed.
2024-04-09
Published