First published: Wed Apr 18 2012(Updated: )
Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before 3.7.2, XR-300 before 3.7.2, and X-300 before 3.7.2 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a malformed URL.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SCALANCE X-414-3E Firmware | <=3.7.0 | |
Siemens SCALANCE X-414-3E Firmware | =1.2.2 | |
Siemens SCALANCE X-414-3E Firmware | =2.1.1 | |
Siemens SCALANCE X-414-3E Firmware | =2.2.0 | |
Siemens SCALANCE X-414-3E Firmware | =2.3.2 | |
Siemens SCALANCE X-414-3E Firmware | =2.3.3 | |
Siemens SCALANCE X-414-3E Firmware | =3.0.0 | |
Siemens SCALANCE X-414-3E Firmware | =3.0.2 | |
Siemens SCALANCE X-414-3E Firmware | =3.3.0 | |
Siemens SCALANCE X-414-3E Firmware | =3.4.0 | |
Siemens Scalance X414-3E Firmware | ||
Siemens Scalance X308-2M | <=3.7.0 | |
Siemens Scalance X308-2M | =3.1.1 | |
Siemens Scalance X308-2M | =3.5.0 | |
Siemens Scalance X308-2M | =3.5.2 | |
Siemens Scalance X308-2M Firmware | ||
Siemens Scalance X-300 Firmware | <=3.7.0 | |
Siemens Scalance X-300 Firmware | =3.5.0 | |
Siemens Scalance XR-300EEC | ||
Siemens Scalance XR-300PoE | <=3.7.0 | |
Siemens Scalance XR-300PoE | =3.1.1 | |
Siemens Scalance XR-300PoE | =3.5.0 | |
Siemens Scalance XR-300 | ||
Siemens Scalance X300 Firmware | <=3.7.0 | |
Siemens Scalance X300 Firmware | =2.2.0 | |
Siemens Scalance X300 Firmware | =2.3.1 | |
Siemens Scalance X300 Firmware | =3.0.0 | |
Siemens Scalance X300 Firmware | =3.3.1 | |
Siemens Scalance X300 Firmware | =3.5.0 | |
Siemens Scalance X300 Firmware | =3.5.1 | |
Siemens SCALANCE X-300 series firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1802 is classified as a high-severity vulnerability due to its potential to cause denial of service and unauthorized execution of arbitrary code.
To fix CVE-2012-1802, you should upgrade the firmware of the affected Siemens SCALANCE devices to version 3.7.1 or later.
CVE-2012-1802 affects several models of Siemens SCALANCE devices, including the X-414-3E, X308-2M, and X-300 series firmware versions prior to specified updates.
Yes, CVE-2012-1802 can be exploited remotely, allowing attackers to trigger a device reboot or potentially execute malicious code.
While there isn't an official workaround, network segmentation and restricting access to the affected devices may help mitigate potential exploitation of CVE-2012-1802.