PT-2019-4791 · Siemens · Scalance Sc-600
Published
2019-08-13
·
Updated
2020-10-02
·
CVE-2019-10928
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SCALANCE SC-600 version V2.0
Description
A vulnerability has been identified that allows an authenticated attacker with physical access to the device and access to port 22/tcp to execute arbitrary commands. The vulnerability can be exploited without user interaction and impacts the confidentiality, integrity, and availability of the device. It is related to incorrect handling of exceptional states, which may allow an attacker to execute arbitrary code.
Recommendations
For SCALANCE SC-600 version V2.0, consider restricting physical access to the device and limiting access to port 22/tcp to minimize the risk of exploitation. As a temporary workaround, consider disabling access to the device until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scalance Sc-600