CVE-2022-26648: High severity siemens scalance x204-2 vulnerability
A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT PRO (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2P IRT (All versions < V5.5.2), SCALANCE X202-2P IRT PRO (All versions < V5.5.2), SCALANCE X204-2 (All versions < V5.2.6), SCALANCE X204-2FM (All versions < V5.2.6), SCALANCE X204-2LD (All versions < V5.2.6), SCALANCE X204-2LD TS (All versions < V5.2.6), SCALANCE X204-2TS (All versions < V5.2.6), SCALANCE X204IRT (All versions < V5.5.2), SCALANCE X204IRT (All versions < V5.5.2), SCALANCE X204IRT PRO (All versions < V5.5.2), SCALANCE X206-1 (All versions < V5.2.6), SCALANCE X206-1LD (All versions < V5.2.6), SCALANCE X208 (All versions < V5.2.6), SCALANCE X208PRO (All versions < V5.2.6), SCALANCE X212-2 (All versions < V5.2.6), SCALANCE X212-2LD (All versions < V5.2.6), SCALANCE X216 (All versions < V5.2.6), SCALANCE X224 (All versions < V5.2.6), SCALANCE XF201-3P IRT (All versions < V5.5.2), SCALANCE XF202-2P IRT (All versions < V5.5.2), SCALANCE XF204 (All versions < V5.2.6), SCALANCE XF204-2 (All versions < V5.2.6), SCALANCE XF204-2BA IRT (All versions < V5.5.2), SCALANCE XF204IRT (All versions < V5.5.2), SCALANCE XF206-1 (All versions < V5.2.6), SCALANCE XF208 (All versions < V5.2.6). Affected devices do not properly validate the GET parameter XNo of incoming HTTP requests. This could allow an unauthenticated remote attacker to crash affected devices.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26648?
The severity of CVE-2022-26648 is categorized as high due to its potential impact on device security and network integrity.
How do I fix CVE-2022-26648?
To fix CVE-2022-26648, update the affected SCALANCE devices to version V5.5.2 or later.
Which devices are affected by CVE-2022-26648?
CVE-2022-26648 affects all versions of SCALANCE X200-4P IRT, X201-3P IRT, X201-3P IRT PRO, and X202-2IRT versions prior to V5.5.2.
What type of vulnerability is CVE-2022-26648?
CVE-2022-26648 is a security vulnerability in Siemens SCALANCE devices that could lead to unauthorized access.
Is there a workaround for CVE-2022-26648 until a patch is applied?
Currently, no specific workaround is outlined for CVE-2022-26648, and updating to the latest firmware is recommended.