First published: Tue Apr 12 2022(Updated: )
A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), SCALANCE W1788-2IA M12 (All versions < V3.0.0). Affected devices do not properly handle resources of ARP requests. This could allow an attacker to cause a race condition that leads to a crash of the entire device.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Scalance W1788-2IA M12 | <3.0.0 | |
Siemens Scalance W1788-2IA | ||
Siemens Scalance W1788-2 Firmware | <3.0.0 | |
Siemens Scalance W1788-2 Firmware | ||
Siemens Scalance W1788-2 EEC M12 | <3.0.0 | |
Siemens Scalance W1788-2 | ||
Siemens SCALANCE W1788-1 M12 Firmware | <3.0.0 | |
Siemens SCALANCE W1788-1 M12 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-27481 is medium with a CVSS score of 5.3.
SCALANCE W1788-1 M12, SCALANCE W1788-2 EEC M12, SCALANCE W1788-2 M12, and SCALANCE W1788-2IA M12 are affected by CVE-2022-27481.
CVE-2022-27481 is a vulnerability in SCALANCE W1788-1 M12, SCALANCE W1788-2 EEC M12, SCALANCE W1788-2 M12, and SCALANCE W1788-2IA M12 devices where affected devices do not properly handle resources of ARP requests.
There is no fix available at the moment. It is recommended to follow the guidance provided by Siemens in their advisory.
You can find more information about CVE-2022-27481 in the Siemens Product CERT advisory.