ZeroHour

CVE-2020-25226

CVSS 3.1
9.8 critical
EPSS
2%p79
Published
()
Modified
Description

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0). The web server of the affected devices contains a vulnerability that may lead to a buffer overflow condition. An attacker could cause this condition on the webserver by sending a specially crafted request. The webserver could stop and not recover anymore.

Vendors
siemens
Products
scalance x200-4pirt firmware, scalance x201-3pirt firmware, scalance x202-2irt firmware, scalance x202-2pirt firmware, scalance x202-2pirt siplus net firmware, scalance x204irt firmware, scalance x307-3 firmware, scalance x307-3ld firmware, scalance x308-2 firmware, scalance x308-2ld firmware, scalance x308-2lh firmware, scalance x308-2lh\+ firmware
Weakness
CWE-122, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.