CVE-2014-8478: Path Traversal
The web server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote attackers to cause a denial of service (reboot) via malformed HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8478?
CVE-2014-8478 is considered a high severity vulnerability that can lead to denial of service by rebooting the affected Siemens devices.
How do I fix CVE-2014-8478?
To mitigate CVE-2014-8478, upgrade the firmware of the Siemens SCALANCE X-300 and X-408 switches to version 4.0 or later.
What devices are affected by CVE-2014-8478?
CVE-2014-8478 affects Siemens SCALANCE X-300 and SCALANCE X-408 switches with firmware versions prior to 4.0.
Can CVE-2014-8478 be exploited remotely?
Yes, CVE-2014-8478 can be exploited remotely through malformed HTTP requests directed at the affected Siemens switches.
Is there a workaround for CVE-2014-8478?
There are no known workarounds for CVE-2014-8478 other than upgrading to the patched firmware version.