CVE-2022-26649: Critical severity siemens scalance x204-2 vulnerability
A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT PRO (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2P IRT (All versions < V5.5.2), SCALANCE X202-2P IRT PRO (All versions < V5.5.2), SCALANCE X204-2 (All versions < V5.2.6), SCALANCE X204-2FM (All versions < V5.2.6), SCALANCE X204-2LD (All versions < V5.2.6), SCALANCE X204-2LD TS (All versions < V5.2.6), SCALANCE X204-2TS (All versions < V5.2.6), SCALANCE X204IRT (All versions < V5.5.2), SCALANCE X204IRT (All versions < V5.5.2), SCALANCE X204IRT PRO (All versions < V5.5.2), SCALANCE X206-1 (All versions < V5.2.6), SCALANCE X206-1LD (All versions < V5.2.6), SCALANCE X208 (All versions < V5.2.6), SCALANCE X208PRO (All versions < V5.2.6), SCALANCE X212-2 (All versions < V5.2.6), SCALANCE X212-2LD (All versions < V5.2.6), SCALANCE X216 (All versions < V5.2.6), SCALANCE X224 (All versions < V5.2.6), SCALANCE XF201-3P IRT (All versions < V5.5.2), SCALANCE XF202-2P IRT (All versions < V5.5.2), SCALANCE XF204 (All versions < V5.2.6), SCALANCE XF204-2 (All versions < V5.2.6), SCALANCE XF204-2BA IRT (All versions < V5.5.2), SCALANCE XF204IRT (All versions < V5.5.2), SCALANCE XF206-1 (All versions < V5.2.6), SCALANCE XF208 (All versions < V5.2.6). Affected devices do not properly validate the URI of incoming HTTP GET requests. This could allow an unauthenticated remote attacker to crash affected devices.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26649?
CVE-2022-26649 is classified with a high severity due to its potential impact on the affected Siemens SCALANCE devices.
How do I fix CVE-2022-26649?
To fix CVE-2022-26649, update the firmware of affected Siemens SCALANCE devices to version 5.5.2 or later.
Which products are affected by CVE-2022-26649?
CVE-2022-26649 affects all versions of SCALANCE X200-4P IRT, X201-3P IRT, X201-3P IRT PRO, X202-2IRT, and others prior to version 5.5.2.
What are the potential risks of CVE-2022-26649?
Exploitation of CVE-2022-26649 could allow unauthorized access to the device, leading to various security risks including data breaches.
Is there a patch available for CVE-2022-26649?
Yes, Siemens has released a firmware update that acts as a patch for CVE-2022-26649.