PT-2025-6204 · Siemens · Scalance Wam766-1 Eec+4

Published

2025-02-11

·

Updated

2025-02-11

·

CVE-2025-24532

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: SCALANCE WAB762-1 versions prior to V3.0.0 SCALANCE WAM763-1 versions prior to V3.0.0 SCALANCE WAM763-1 (ME) versions prior to V3.0.0 SCALANCE WAM763-1 (US) versions prior to V3.0.0 SCALANCE WAM766-1 versions prior to V3.0.0 SCALANCE WAM766-1 (ME) versions prior to V3.0.0 SCALANCE WAM766-1 (US) versions prior to V3.0.0 SCALANCE WAM766-1 EEC versions prior to V3.0.0 SCALANCE WAM766-1 EEC (ME) versions prior to V3.0.0 SCALANCE WAM766-1 EEC (US) versions prior to V3.0.0 SCALANCE WUB762-1 versions prior to V3.0.0 SCALANCE WUB762-1 iFeatures versions prior to V3.0.0 SCALANCE WUM763-1 versions prior to V3.0.0 SCALANCE WUM763-1 (US) versions prior to V3.0.0 SCALANCE WUM766-1 versions prior to V3.0.0 SCALANCE WUM766-1 (ME) versions prior to V3.0.0 SCALANCE WUM766-1 (USA) versions prior to V3.0.0
Description: The issue is related to incorrect authorization in SNMPv3 View configuration, which could allow an attacker to change the View Type of SNMPv3 Views. Devices with a role user are affected by this issue.
Recommendations: For SCALANCE WAB762-1 versions prior to V3.0.0, update to version V3.0.0 or later. For SCALANCE WAM763-1 versions prior to V3.0.0, update to version V3.0.0 or later. For SCALANCE WAM763-1 (ME) versions prior to V3.0.0, update to version V3.0.0 or later. For SCALANCE WAM763-1 (US) versions prior to V3.0.0, update to version V3.0.0 or later. For SCALANCE WAM766-1 versions prior to V3.0.0, update to version V3.0.0 or later. For SCALANCE WAM766-1 (ME) versions prior to V3.0.0, update to version V3.0.0 or later. For SCALANCE WAM766-1 (US) versions prior to V3.0.0, update to version V3.0.0 or later. For SCALANCE WAM766-1 EEC versions prior to V3.0.0, update to version V3.0.0 or later. For SCALANCE WAM766-1 EEC (ME) versions prior to V3.0.0, update to version V3.0.0 or later. For SCALANCE WAM766-1 EEC (US) versions prior to V3.0.0, update to version V3.0.0 or later. For SCALANCE WUB762-1 versions prior to V3.0.0, update to version V3.0.0 or later. For SCALANCE WUB762-1 iFeatures versions prior to V3.0.0, update to version V3.0.0 or later. For SCALANCE WUM763-1 versions prior to V3.0.0, update to version V3.0.0 or later. For SCALANCE WUM763-1 (US) versions prior to V3.0.0, update to version V3.0.0 or later. For SCALANCE WUM766-1 versions prior to V3.0.0, update to version V3.0.0 or later. For SCALANCE WUM766-1 (ME) versions prior to V3.0.0, update to version V3.0.0 or later. For SCALANCE WUM766-1 (USA) versions prior to V3.0.0, update to version V3.0.0 or later.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2025-05907
CVE-2025-24532

Affected Products

Scalance Wab762-1
Scalance Wam763-1
Scalance Wam766-1
Scalance Wam766-1 Eec
Scalance Wub762-1 Ifeatures