ZeroHour

CVE-2022-36323

CVSS 3.1
9.1 critical
EPSS
2%p76
Published
()
Modified
Description

Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.

Vendors
siemens
Products
scalance m-800 firmware, scalance s615 firmware, scalance sc-600 firmware, scalance sc622-2c firmware, scalance sc632-2c firmware, scalance sc636-2c firmware, scalance sc642-2c firmware, scalance sc646-2c firmware, scalance w700 ieee 802.11ax firmware, scalance w700 ieee 802.11n firmware, scalance w700 ieee 802.11ac firmware, scalance xb-200 firmware
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.