PT-2022-5344 · Siemens · Scalance M812-1+13

Martin Grubhofer

+1

·

Published

2022-10-11

·

Updated

2023-03-14

·

CVE-2022-31766

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions RUGGEDCOM RM1224 LTE(4G) EU versions prior to V7.1.2 RUGGEDCOM RM1224 LTE(4G) NAM versions prior to V7.1.2 SCALANCE M804PB versions prior to V7.1.2 SCALANCE M812-1 ADSL-Router versions prior to V7.1.2 SCALANCE M816-1 ADSL-Router versions prior to V7.1.2 SCALANCE M826-2 SHDSL-Router versions prior to V7.1.2 SCALANCE M874-2 versions prior to V7.1.2 SCALANCE M874-3 versions prior to V7.1.2 SCALANCE M876-3 versions prior to V7.1.2 SCALANCE M876-4 versions prior to V7.1.2 SCALANCE MUM853-1 versions prior to V7.1.2 SCALANCE MUM856-1 versions prior to V7.1.2 SCALANCE S615 versions prior to V7.1.2 SCALANCE WAM763-1 versions V1.1.0 through V2.9.9 SCALANCE WAM766-1 versions V1.1.0 through V2.9.9 SCALANCE WUM763-1 versions V1.1.0 through V2.9.9 SCALANCE WUM766-1 versions V1.1.0 through V2.9.9
Description The issue exists due to insufficient input validation in the software of certain Siemens routers, access points, and routers. This could allow a remote attacker to cause a denial of service condition and reboot the device, potentially affecting other network resources. Affected devices with the TCP Event service enabled do not properly handle malformed packets.
Recommendations For RUGGEDCOM RM1224 LTE(4G) EU versions prior to V7.1.2, update to version V7.1.2 or later. For RUGGEDCOM RM1224 LTE(4G) NAM versions prior to V7.1.2, update to version V7.1.2 or later. For SCALANCE M804PB versions prior to V7.1.2, update to version V7.1.2 or later. For SCALANCE M812-1 ADSL-Router versions prior to V7.1.2, update to version V7.1.2 or later. For SCALANCE M816-1 ADSL-Router versions prior to V7.1.2, update to version V7.1.2 or later. For SCALANCE M826-2 SHDSL-Router versions prior to V7.1.2, update to version V7.1.2 or later. For SCALANCE M874-2 versions prior to V7.1.2, update to version V7.1.2 or later. For SCALANCE M874-3 versions prior to V7.1.2, update to version V7.1.2 or later. For SCALANCE M876-3 versions prior to V7.1.2, update to version V7.1.2 or later. For SCALANCE M876-4 versions prior to V7.1.2, update to version V7.1.2 or later. For SCALANCE MUM853-1 versions prior to V7.1.2, update to version V7.1.2 or later. For SCALANCE MUM856-1 versions prior to V7.1.2, update to version V7.1.2 or later. For SCALANCE S615 versions prior to V7.1.2, update to version V7.1.2 or later. For SCALANCE WAM763-1 versions V1.1.0 through V2.9.9, update to version V3.0.0 or later. For SCALANCE WAM766-1 versions V1.1.0 through V2.9.9, update to version V3.0.0 or later. For SCALANCE WUM763-1 versions V1.1.0 through V2.9.9, update to version V3.0.0 or later. For SCALANCE WUM766-1 versions V1.1.0 through V2.9.9, update to version V3.0.0 or later. As a temporary workaround, consider disabling the TCP Event service until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06658
CVE-2022-31766

Affected Products

Ruggedcom Rm1224
Scalance M804Pb
Scalance M812-1
Scalance M816-1
Scalance M826-2
Scalance M874-2
Scalance M874-3
Scalance M876-3
Scalance M876-4
Scalance Mum853-1
Scalance Mum856-1
Scalance S615
Scalance Wam763-1
Scalance Wam766-1