9.8
CVE-2020-15800
- EPSS 0.85%
- Veröffentlicht 12.01.2021 21:15:16
- Zuletzt bearbeitet 21.11.2024 05:06:12
- Quelle productcert@siemens.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). The webserver of the affected devices contains a vulnerability that may lead to a heap overflow condition. An attacker could cause this condition on the webserver by sending specially crafted requests. This could stop the webserver temporarily.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Scalance X200-4pirt Firmware Version < 5.5.0
Siemens ≫ Scalance X201-3pirt Firmware Version < 5.5.0
Siemens ≫ Scalance X202-2irt Firmware Version < 5.5.0
Siemens ≫ Scalance X202-2pirt Firmware Version < 5.5.0
Siemens ≫ Scalance X202-2pirt Siplus Net Firmware Version < 5.5.0
Siemens ≫ Scalance X204irt Firmware Version < 5.5.0
Siemens ≫ Scalance Xb205-3 Firmware Version < 5.2.5
Siemens ≫ Scalance Xb205-3ld Firmware Version < 5.2.5
Siemens ≫ Scalance Xb208 Firmware Version < 5.2.5
Siemens ≫ Scalance Xb213-3 Firmware Version < 5.2.5
Siemens ≫ Scalance Xb213-3ld Firmware Version < 5.2.5
Siemens ≫ Scalance Xb216 Firmware Version < 5.2.5
Siemens ≫ Scalance Xc206-2 Firmware Version < 5.2.5
Siemens ≫ Scalance Xc206-2g Poe Firmware Version < 5.2.5
Siemens ≫ Scalance Xc206-2g Poe Eec Firmware Version < 5.2.5
Siemens ≫ Scalance Xc206-2sfp Firmware Version < 5.2.5
Siemens ≫ Scalance Xc206-2sfp Eec Firmware Version < 5.2.5
Siemens ≫ Scalance Xc206-2sfp G Firmware Version < 5.2.5
Siemens ≫ Scalance Xc206-2sfp G (e/ip) Firmware Version < 5.2.5
Siemens ≫ Scalance Xc206-2sfp G Eec Firmware Version < 5.2.5
Siemens ≫ Scalance Xc208 Firmware Version < 5.2.5
Siemens ≫ Scalance Xc208eec Firmware Version < 5.2.5
Siemens ≫ Scalance Xc208g Firmware Version < 5.2.5
Siemens ≫ Scalance Xc208g (e/ip) Firmware Version < 5.2.5
Siemens ≫ Scalance Xc208g Eec Firmware Version < 5.2.5
Siemens ≫ Scalance Xc208g Poe Firmware Version < 5.2.5
Siemens ≫ Scalance Xc216 Firmware Version < 5.2.5
Siemens ≫ Scalance Xc216-4c Firmware Version < 5.2.5
Siemens ≫ Scalance Xc216-4c G Firmware Version < 5.2.5
Siemens ≫ Scalance Xc216-4c G (e/ip) Firmware Version < 5.2.5
Siemens ≫ Scalance Xc216-4c G Eec Firmware Version < 5.2.5
Siemens ≫ Scalance Xc216eec Firmware Version < 5.2.5
Siemens ≫ Scalance Xc224-4c G Firmware Version < 5.2.5
Siemens ≫ Scalance Xc224-4c G (e/ip) Firmware Version < 5.2.5
Siemens ≫ Scalance Xc224-4c G Eec Firmware Version < 5.2.5
Siemens ≫ Scalance Xc224 Firmware Version < 5.2.5
Siemens ≫ Scalance Xf201-3p Irt Firmware Version < 5.2.5
Siemens ≫ Scalance Xf202-2p Irt Firmware Version < 5.2.5
Siemens ≫ Scalance Xf204 Firmware Version < 5.2.5
Siemens ≫ Scalance Xf204-2 Firmware Version < 5.2.5
Siemens ≫ Scalance Xf204-2ba Dna Firmware Version < 5.2.5
Siemens ≫ Scalance Xf204-2ba Irt Firmware Version < 5.2.5
Siemens ≫ Scalance Xf204 Dna Firmware Version < 5.2.5
Siemens ≫ Scalance Xf204irt Firmware Version < 5.2.5
Siemens ≫ Scalance Xf206-1 Firmware Version < 5.2.5
Siemens ≫ Scalance Xf208 Firmware Version < 5.2.5
Siemens ≫ Scalance Xp208 Firmware Version < 5.2.5
Siemens ≫ Scalance Xp208 (eip) Firmware Version < 5.2.5
Siemens ≫ Scalance Xp208eec Firmware Version < 5.2.5
Siemens ≫ Scalance Xp208poe Eec Firmware Version < 5.2.5
Siemens ≫ Scalance Xp216 Firmware Version < 5.2.5
Siemens ≫ Scalance Xp216 (eip) Firmware Version < 5.2.5
Siemens ≫ Scalance Xp216eec Firmware Version < 5.2.5
Siemens ≫ Scalance Xp216poe Eec Firmware Version < 5.2.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.85% | 0.738 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-122 Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.