First published: Tue Jan 12 2021(Updated: )
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0). The vulnerability could allow an unauthenticated attacker to reboot the device over the network by using special urls from integrated web server of the affected products.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SCALANCE X200-4PIRT | <5.5.0 | |
Siemens SCALANCE X-200 Firmware | ||
Siemens SCALANCE X201-3P IRT Firmware | <5.5.0 | |
Siemens Scalance X201-3P IRT Pro Firmware | ||
Siemens Scalance X202-2P IRT PRO Firmware | <5.5.0 | |
Siemens Scalance X202-2P IRT PRO Firmware | ||
Siemens SCALANCE X202-2PIRT SIPLUS NET Firmware | <5.5.0 | |
Siemens SCALANCE X202-2P IRT SIPLUS NET | ||
Siemens SIPLUS NET SCALANCE X202-2P IRT | <5.5.0 | |
Siemens SCALANCE X202-2P IRT SIPLUS NET | ||
Siemens SCALANCE X204IRT | <5.5.0 | |
Siemens Scalance X-200IRT | ||
Siemens Scalance X307-3 | ||
Siemens Scalance X307-3 Firmware | ||
Siemens Scalance X307-3LD Firmware | ||
siemens scalance x307-3ld | ||
Siemens SIPLUS NET SCALANCE X308-2 firmware | ||
Siemens Scalance X308-2M PoE | ||
Siemens Scalance X308-2LD | ||
Siemens Scalance X308-2LD | ||
Siemens Scalance X308-2LH | ||
Siemens Scalance X308-2LH | ||
Siemens Scalance X308-2LH+ Firmware | ||
Siemens Scalance X308-2LH+ | ||
Siemens Scalance X308-2M | ||
Siemens Scalance X308-2M Firmware | ||
Siemens Scalance X308-2M PoE | ||
Siemens Scalance X308-2M TS Firmware | ||
Siemens Scalance X310 | ||
Siemens Scalance X310 | ||
Siemens Scalance X310FE | ||
Siemens Scalance X310FE | ||
Siemens Scalance X320-1FE | ||
Siemens Scalance X320-1FE | ||
Siemens Scalance X320-3LDFE Firmware | ||
Siemens Scalance X320-3LDFE Firmware | ||
Siemens Scalance XB205-3 | <5.2.5 | |
Siemens Scalance XB205-3 Firmware | ||
Siemens Scalance XB205-3LD | <5.2.5 | |
Siemens Scalance XB205-3 | ||
Siemens Scalance XB208 | <5.2.5 | |
Siemens Scalance XB208 | ||
Siemens Scalance XB213-3 | <5.2.5 | |
Siemens Scalance XB213-3LD Firmware | ||
Siemens Scalance XB213-3LD | <5.2.5 | |
Siemens Scalance XB213-3LD Firmware | ||
Siemens Scalance XB216 | <5.2.5 | |
Siemens Scalance XB216 Firmware | ||
Siemens Scalance XC206-2 | <5.2.5 | |
Siemens Scalance XC206-2 Firmware | ||
Siemens Scalance XC206-2G PoE | <5.2.5 | |
Siemens Scalance XC206-2G PoE Firmware | ||
Siemens Scalance XC206-2G PoE EEC | <5.2.5 | |
Siemens Scalance XC206-2G PoE EEC Firmware | ||
Siemens Scalance XC206-2SFP | <5.2.5 | |
Siemens Siplus Net Scalance XC206-2SFP | ||
Siemens Scalance XC206-2SFP EEC Firmware | <5.2.5 | |
Siemens Scalance XC206-2SFP EEC Firmware | ||
Siemens Scalance XC206-2SFP G (E/IP) Firmware | <5.2.5 | |
Siemens Scalance XC206-2SFP G (E/IP) | ||
Siemens Scalance XC206-2SFP G (E/IP) Firmware | <5.2.5 | |
Siemens Scalance XC206-2SFP G (E/IP) | ||
Siemens Scalance XC206-2SFP G Firmware | <5.2.5 | |
Siemens Scalance XC206-2SFP G EEC Firmware | ||
Siemens Siplus Net Scalance XC208 Firmware | <5.2.5 | |
Siemens Siplus Net Scalance XC208 | ||
Siemens SCALANCE XC208 EEC Firmware | <5.2.5 | |
Siemens SCALANCE XC208 EEC Firmware | ||
Siemens Scalance XC208G (E/IP) | <5.2.5 | |
Siemens Scalance XC208G (E/IP) | ||
Siemens Scalance XC208G (E/IP) Firmware | <5.2.5 | |
Siemens Scalance XC208G (E/IP) | ||
Siemens SCALANCE XC208G (EIP DEF.) | <5.2.5 | |
Siemens Scalance XC208G (E/IP) | ||
Siemens Scalance XC208G PoE | <5.2.5 | |
Siemens SCALANCE XC208G PoE (54 V DC) | ||
Siemens Scalance XC216EEC Firmware | <5.2.5 | |
Siemens SCALANCE XC216-3G PoE (54 V DC) | ||
Siemens Scalance XC216-4C | <5.2.5 | |
Siemens Scalance XC216-4C Firmware | ||
Siemens Scalance XC216-4C G (E/IP) Firmware | <5.2.5 | |
Siemens Scalance XC216-4C G (E/IP) | ||
Siemens Scalance XC216-4C G (E/IP) | <5.2.5 | |
Siemens Scalance XC216-4C G (E/IP) | ||
Siemens Scalance XC216-4C G EEC | <5.2.5 | |
Siemens Scalance XC216-4C Firmware | ||
Siemens Scalance XC216EEC | <5.2.5 | |
Siemens Scalance XC216EEC Firmware | ||
Siemens Scalance XC224-4C G EEC Firmware | <5.2.5 | |
Siemens Scalance XC224-4C G EEC Firmware | ||
Siemens Scalance XC224-4C G (E/IP) Firmware | <5.2.5 | |
Siemens Scalance XC224-4C G (E/IP) | ||
Siemens Scalance XC224-4C G EEC | <5.2.5 | |
Siemens Scalance XC224-4C G EEC Firmware | ||
Siemens Scalance Xc224 Firmware | <5.2.5 | |
Siemens SCALANCE XC224-4C G | ||
Siemens Scalance XF201-3P IRT | <5.2.5 | |
Siemens Scalance XF201-3P IRT Firmware | ||
Siemens Scalance XF202-2P IRT | <5.2.5 | |
Siemens Scalance XF202-2P IRT Firmware | ||
Siemens Scalance XF204 Firmware | <5.2.5 | |
Siemens Scalance XF204 | ||
Siemens Scalance XF204-2 Firmware | <5.2.5 | |
Siemens Scalance XF204-2 | ||
Siemens Scalance XF204-2BA DNA | <5.2.5 | |
Siemens Scalance XF204-2BA DNA | ||
Siemens Scalance XF204-2BA IRT | <5.2.5 | |
Siemens Scalance XF204-2BA IRT | ||
Siemens Scalance XF204 DNA | <5.2.5 | |
Siemens Scalance XF204 DNA | ||
Siemens SCALANCE XF204 IRT | <5.2.5 | |
Siemens SCALANCE XF204 IRT | ||
Siemens Scalance XF206-1 | <5.2.5 | |
Siemens Scalance XF206-1 Firmware | ||
Siemens Scalance XF208 | <5.2.5 | |
Siemens Scalance XF208 Firmware | ||
Siemens SCALANCE XP208 (Ethernet/IP) | <5.2.5 | |
Siemens Scalance XP208 (EIP) | ||
Siemens Scalance XP208 (EIP) Firmware | <5.2.5 | |
Siemens Scalance XP208 (EIP) | ||
Siemens Scalance XP208EEC | <5.2.5 | |
Siemens Scalance XP208EEC Firmware | ||
Siemens SCALANCE XP208PoE EEC | <5.2.5 | |
Siemens SCALANCE XP208PoE EEC Firmware | ||
Siemens Scalance XP216 (EIP) Firmware | <5.2.5 | |
Siemens Scalance XP216 Firmware | ||
Siemens Scalance XP216 (EIP) Firmware | <5.2.5 | |
Siemens Scalance XP216 (EIP) | ||
Siemens Scalance XP216EEC | <5.2.5 | |
Siemens Scalance XP216EEC Firmware | ||
Siemens Scalance XP216PoE EEC | <5.2.5 | |
Siemens Scalance XP216PoE EEC Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15799 has been assigned a moderate severity level, potentially allowing unauthorized users to reboot affected devices.
To fix CVE-2020-15799, update your SCALANCE X-200 switch family firmware to version 5.2.5 or higher.
CVE-2020-15799 affects all versions of SCALANCE X-200 and SCALANCE X-200IRT switch families prior to specified firmware versions.
Yes, CVE-2020-15799 can be exploited remotely by an unauthenticated attacker.
CVE-2020-15799 can lead to device instability due to unauthorized reboots, impacting network availability and reliability.