PT-2022-5344 · Siemens · Scalance M812-1+13
Martin Grubhofer
+1
·
Published
2022-10-11
·
Updated
2023-03-14
·
CVE-2022-31766
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
RUGGEDCOM RM1224 LTE(4G) EU versions prior to V7.1.2
RUGGEDCOM RM1224 LTE(4G) NAM versions prior to V7.1.2
SCALANCE M804PB versions prior to V7.1.2
SCALANCE M812-1 ADSL-Router versions prior to V7.1.2
SCALANCE M816-1 ADSL-Router versions prior to V7.1.2
SCALANCE M826-2 SHDSL-Router versions prior to V7.1.2
SCALANCE M874-2 versions prior to V7.1.2
SCALANCE M874-3 versions prior to V7.1.2
SCALANCE M876-3 versions prior to V7.1.2
SCALANCE M876-4 versions prior to V7.1.2
SCALANCE MUM853-1 versions prior to V7.1.2
SCALANCE MUM856-1 versions prior to V7.1.2
SCALANCE S615 versions prior to V7.1.2
SCALANCE WAM763-1 versions V1.1.0 through V2.9.9
SCALANCE WAM766-1 versions V1.1.0 through V2.9.9
SCALANCE WUM763-1 versions V1.1.0 through V2.9.9
SCALANCE WUM766-1 versions V1.1.0 through V2.9.9
Description
The issue exists due to insufficient input validation in the software of certain Siemens routers, access points, and routers. This could allow a remote attacker to cause a denial of service condition and reboot the device, potentially affecting other network resources. Affected devices with the TCP Event service enabled do not properly handle malformed packets.
Recommendations
For RUGGEDCOM RM1224 LTE(4G) EU versions prior to V7.1.2, update to version V7.1.2 or later.
For RUGGEDCOM RM1224 LTE(4G) NAM versions prior to V7.1.2, update to version V7.1.2 or later.
For SCALANCE M804PB versions prior to V7.1.2, update to version V7.1.2 or later.
For SCALANCE M812-1 ADSL-Router versions prior to V7.1.2, update to version V7.1.2 or later.
For SCALANCE M816-1 ADSL-Router versions prior to V7.1.2, update to version V7.1.2 or later.
For SCALANCE M826-2 SHDSL-Router versions prior to V7.1.2, update to version V7.1.2 or later.
For SCALANCE M874-2 versions prior to V7.1.2, update to version V7.1.2 or later.
For SCALANCE M874-3 versions prior to V7.1.2, update to version V7.1.2 or later.
For SCALANCE M876-3 versions prior to V7.1.2, update to version V7.1.2 or later.
For SCALANCE M876-4 versions prior to V7.1.2, update to version V7.1.2 or later.
For SCALANCE MUM853-1 versions prior to V7.1.2, update to version V7.1.2 or later.
For SCALANCE MUM856-1 versions prior to V7.1.2, update to version V7.1.2 or later.
For SCALANCE S615 versions prior to V7.1.2, update to version V7.1.2 or later.
For SCALANCE WAM763-1 versions V1.1.0 through V2.9.9, update to version V3.0.0 or later.
For SCALANCE WAM766-1 versions V1.1.0 through V2.9.9, update to version V3.0.0 or later.
For SCALANCE WUM763-1 versions V1.1.0 through V2.9.9, update to version V3.0.0 or later.
For SCALANCE WUM766-1 versions V1.1.0 through V2.9.9, update to version V3.0.0 or later.
As a temporary workaround, consider disabling the TCP Event service until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ruggedcom Rm1224
Scalance M804Pb
Scalance M812-1
Scalance M816-1
Scalance M826-2
Scalance M874-2
Scalance M874-3
Scalance M876-3
Scalance M876-4
Scalance Mum853-1
Scalance Mum856-1
Scalance S615
Scalance Wam763-1
Scalance Wam766-1