PT-2025-24675 · Siemens · Scalance Xr326-8+20
Published
2025-06-10
·
Updated
2025-06-10
·
CVE-2025-40567
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
RUGGEDCOM RST2428P versions prior to V3.2
SCALANCE XC316-8 versions prior to V3.2
SCALANCE XC324-4 versions prior to V3.2
SCALANCE XC324-4 EEC versions prior to V3.2
SCALANCE XC332 versions prior to V3.2
SCALANCE XC416-8 versions prior to V3.2
SCALANCE XC424-4 versions prior to V3.2
SCALANCE XC432 versions prior to V3.2
SCALANCE XCH328 versions prior to V3.2
SCALANCE XCM324 versions prior to V3.2
SCALANCE XCM328 versions prior to V3.2
SCALANCE XCM332 versions prior to V3.2
SCALANCE XR302-32 versions prior to V3.2
SCALANCE XR322-12 versions prior to V3.2
SCALANCE XR326-8 versions prior to V3.2
SCALANCE XR326-8 EEC versions prior to V3.2
SCALANCE XR502-32 versions prior to V3.2
SCALANCE XR522-12 versions prior to V3.2
SCALANCE XR526-8 versions prior to V3.2
SCALANCE XRH334 versions prior to V3.2
SCALANCE XRM334 versions prior to V3.2
Description
The "Load Rollback" functionality in the web interface of affected products contains an incorrect authorization check. This could allow an authenticated remote attacker with a "guest" role to make the affected product roll back configuration changes made by privileged users.
Recommendations
For RUGGEDCOM RST2428P versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XC316-8 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XC324-4 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XC324-4 EEC versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XC332 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XC416-8 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XC424-4 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XC432 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XCH328 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XCM324 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XCM328 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XCM332 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XR302-32 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XR322-12 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XR326-8 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XR326-8 EEC versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XR502-32 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XR522-12 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XR526-8 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XRH334 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
For SCALANCE XRM334 versions prior to V3.2, update to version V3.2 or later to resolve the issue.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ruggedcom Rst2428P
Scalance Xc316-8
Scalance Xc324-4
Scalance Xr324-4M Eec
Scalance Xc332
Scalance Xc416-8
Scalance Xc424-4
Scalance Xc432
Scalance Xch328
Scalance Xcm324
Scalance Xcm328
Scalance Xcm332
Scalance Xr302-32
Scalance Xr322-12
Scalance Xr326-8
Scalance Xr326-8 Eec
Scalance Xr502-32
Scalance Xr522-12
Scalance Xr526-8C
Scalance Xrh334
Scalance Xrm334