First published: Tue Apr 12 2022(Updated: )
A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), SCALANCE W1788-2IA M12 (All versions < V3.0.0). Affected devices do not properly handle malformed Multicast LLC frames. This could allow an attacker to trigger a denial of service condition.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Scalance W1788-2IA M12 | <3.0.0 | |
Siemens Scalance W1788-2IA | ||
Siemens Scalance W1788-2 Firmware | <3.0.0 | |
Siemens Scalance W1788-2 Firmware | ||
Siemens Scalance W1788-2 EEC M12 | <3.0.0 | |
Siemens Scalance W1788-2 | ||
Siemens SCALANCE W1788-1 M12 Firmware | <3.0.0 | |
Siemens SCALANCE W1788-1 M12 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-28328.
The severity of CVE-2022-28328 is high with a CVSS score of 7.5.
Devices affected by CVE-2022-28328 include SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), and SCALANCE W1788-2IA M12 (All versions < V3.0.0).
The affected devices do not properly handle malformed Multicast LLC frames.
To fix CVE-2022-28328, you should update the firmware of the affected devices to version 3.0.0 or above.