5.9

CVE-2020-28391

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-200RNA switch family (All versions < V3.2.7). Devices create a new unique key upon factory reset, except when used with C-PLUG. When used with C-PLUG the devices use the hardcoded private RSA-key shipped with the firmware-image. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SiemensScalance X200-4pirt Firmware Version < 5.5.0
   SiemensScalance X200-4pirt Version-
SiemensScalance X201-3pirt Firmware Version < 5.5.0
   SiemensScalance X201-3pirt Version-
SiemensScalance X202-2irt Firmware Version < 5.5.0
   SiemensScalance X202-2irt Version-
SiemensScalance X202-2pirt Firmware Version < 5.5.0
   SiemensScalance X202-2pirt Version-
SiemensScalance X204irt Firmware Version < 5.5.0
   SiemensScalance X204irt Version-
SiemensScalance Xb205-3 Firmware Version < 5.2.5
   SiemensScalance Xb205-3 Version-
SiemensScalance Xb205-3ld Firmware Version < 5.2.5
   SiemensScalance Xb205-3ld Version-
SiemensScalance Xb208 Firmware Version < 5.2.5
   SiemensScalance Xb208 Version-
SiemensScalance Xb213-3 Firmware Version < 5.2.5
   SiemensScalance Xb213-3 Version-
SiemensScalance Xb213-3ld Firmware Version < 5.2.5
   SiemensScalance Xb213-3ld Version-
SiemensScalance Xb216 Firmware Version < 5.2.5
   SiemensScalance Xb216 Version-
SiemensScalance Xc206-2 Firmware Version < 5.2.5
   SiemensScalance Xc206-2 Version-
SiemensScalance Xc206-2sfp Firmware Version < 5.2.5
   SiemensScalance Xc206-2sfp Version-
SiemensScalance Xc208 Firmware Version < 5.2.5
   SiemensScalance Xc208 Version-
SiemensScalance Xc208eec Firmware Version < 5.2.5
   SiemensScalance Xc208eec Version-
SiemensScalance Xc208g Firmware Version < 5.2.5
   SiemensScalance Xc208g Version-
SiemensScalance Xc208g Eec Firmware Version < 5.2.5
   SiemensScalance Xc208g Eec Version-
SiemensScalance Xc208g Poe Firmware Version < 5.2.5
   SiemensScalance Xc208g Poe Version-
SiemensScalance Xc216 Firmware Version < 5.2.5
   SiemensScalance Xc216 Version-
SiemensScalance Xc216-4c Firmware Version < 5.2.5
   SiemensScalance Xc216-4c Version-
SiemensScalance Xc216-4c G Firmware Version < 5.2.5
   SiemensScalance Xc216-4c G Version-
SiemensScalance Xc216eec Firmware Version < 5.2.5
   SiemensScalance Xc216eec Version-
SiemensScalance Xc224-4c G Firmware Version < 5.2.5
   SiemensScalance Xc224-4c G Version-
SiemensScalance Xc224 Firmware Version < 5.2.5
   SiemensScalance Xc224 Version-
SiemensScalance Xf204 Firmware Version < 5.2.5
   SiemensScalance Xf204 Version-
SiemensScalance Xf204-2 Firmware Version < 5.2.5
   SiemensScalance Xf204-2 Version-
SiemensScalance Xf204 Dna Firmware Version < 5.2.5
   SiemensScalance Xf204 Dna Version-
SiemensScalance Xf204irt Firmware Version < 5.2.5
   SiemensScalance Xf204irt Version-
SiemensScalance Xf206-1 Firmware Version < 5.2.5
   SiemensScalance Xf206-1 Version-
SiemensScalance Xf208 Firmware Version < 5.2.5
   SiemensScalance Xf208 Version-
SiemensScalance Xp208 Firmware Version < 5.2.5
   SiemensScalance Xp208 Version-
SiemensScalance Xp208 (eip) Firmware Version < 5.2.5
   SiemensScalance Xp208 (eip) Version-
SiemensScalance Xp208eec Firmware Version < 5.2.5
   SiemensScalance Xp208eec Version-
SiemensScalance Xp216 Firmware Version < 5.2.5
   SiemensScalance Xp216 Version-
SiemensScalance Xp216 (eip) Firmware Version < 5.2.5
   SiemensScalance Xp216 (eip) Version-
SiemensScalance Xp216eec Firmware Version < 5.2.5
   SiemensScalance Xp216eec Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.323
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-321 Use of Hard-coded Cryptographic Key

The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.

CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.