CVE-2012-1802: Buffer Overflow
Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before 3.7.2, XR-300 before 3.7.2, and X-300 before 3.7.2 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a malformed URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1802?
CVE-2012-1802 is classified as a high-severity vulnerability due to its potential to cause denial of service and unauthorized execution of arbitrary code.
How do I fix CVE-2012-1802?
To fix CVE-2012-1802, you should upgrade the firmware of the affected Siemens SCALANCE devices to version 3.7.1 or later.
What devices are affected by CVE-2012-1802?
CVE-2012-1802 affects several models of Siemens SCALANCE devices, including the X-414-3E, X308-2M, and X-300 series firmware versions prior to specified updates.
Can CVE-2012-1802 be exploited remotely?
Yes, CVE-2012-1802 can be exploited remotely, allowing attackers to trigger a device reboot or potentially execute malicious code.
Is there a workaround for CVE-2012-1802 if I cannot update immediately?
While there isn't an official workaround, network segmentation and restricting access to the affected devices may help mitigate potential exploitation of CVE-2012-1802.