CVE-2022-28328: Input Validation
A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), SCALANCE W1788-2IA M12 (All versions < V3.0.0). Affected devices do not properly handle malformed Multicast LLC frames. This could allow an attacker to trigger a denial of service condition.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-28328.
What is the severity of CVE-2022-28328?
The severity of CVE-2022-28328 is high with a CVSS score of 7.5.
Which devices are affected by CVE-2022-28328?
Devices affected by CVE-2022-28328 include SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), and SCALANCE W1788-2IA M12 (All versions < V3.0.0).
What is the vulnerability in these affected devices?
The affected devices do not properly handle malformed Multicast LLC frames.
How can I fix CVE-2022-28328?
To fix CVE-2022-28328, you should update the firmware of the affected devices to version 3.0.0 or above.