First published: Tue Oct 11 2022(Updated: )
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.1.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.1.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V7.1.2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V7.1.2), SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2) (All versions < V7.1.2), SCALANCE M816-1 ADSL-Router (6GK5816-1AA00-2AA2) (All versions < V7.1.2), SCALANCE M816-1 ADSL-Router (6GK5816-1BA00-2AA2) (All versions < V7.1.2), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V7.1.2), SCALANCE M874-2 (6GK5874-2AA00-2AA2) (All versions < V7.1.2), SCALANCE M874-3 (6GK5874-3AA00-2AA2) (All versions < V7.1.2), SCALANCE M876-3 (6GK5876-3AA02-2BA2) (All versions < V7.1.2), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (All versions < V7.1.2), SCALANCE M876-4 (6GK5876-4AA10-2BA2) (All versions < V7.1.2), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (All versions < V7.1.2), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (All versions < V7.1.2), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (All versions < V7.1.2), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (All versions < V7.1.2), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (All versions < V7.1.2), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2) (All versions < V7.1.2), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2) (All versions < V7.1.2), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) (All versions >= V1.1.0 < V3.0.0), SCALANCE WAM766-1 (6GK5766-1GE00-7DA0) (All versions >= V1.1.0 < V3.0.0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0) (All versions >= V1.1.0 < V3.0.0), SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0) (All versions >= V1.1.0 < V3.0.0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0) (All versions >= V1.1.0 < V3.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0) (All versions >= V1.1.0 < V3.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0) (All versions >= V1.1.0 < V3.0.0), SCALANCE WUM766-1 (6GK5766-1GE00-3DA0) (All versions >= V1.1.0 < V3.0.0), SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0) (All versions >= V1.1.0 < V3.0.0). Affected devices with TCP Event service enabled do not properly handle malformed packets. This could allow an unauthenticated remote attacker to cause a denial of service condition and reboot the device thus possibly affecting other network resources.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Ruggedcom RM1224 LTE (4G) NAM | <7.1.2 | |
Siemens Ruggedcom RM1224 LTE(4G) EU | ||
siemens scalance m804pb firmware | <7.1.2 | |
Siemens SCALANCE M804PB | ||
Siemens SCALANCE M812-1 | <7.1.2 | |
Siemens SCALANCE M812-1 | ||
Siemens SCALANCE M816-1 (Annex A) | <7.1.2 | |
siemens scalance m816-1 | ||
siemens scalance m826-2 firmware | <7.1.2 | |
siemens scalance m826-2 | ||
siemens scalance m874-2 firmware | <7.1.2 | |
siemens scalance m874-2 | ||
siemens scalance m874-3 firmware | <7.1.2 | |
Siemens SCALANCE M874-3 | ||
siemens scalance m876-3 firmware | <7.1.2 | |
siemens scalance m876-3 | ||
siemens scalance m876-4 firmware | <7.1.2 | |
Siemens SCALANCE M876-4 (EU) Firmware | ||
Siemens Scalance MUM853-1 Firmware | <7.1.2 | |
Siemens Scalance MUM853-1 Firmware | ||
Siemens SCALANCE MUM856-1 (EU) Firmware | <7.1.2 | |
Siemens SCALANCE MUM856-1 | ||
Siemens Scalance S615 Firmware | <7.1.2 | |
Siemens SCALANCE S615 firmware | ||
Siemens Scalance WAM763-1 | >=1.1.0 | |
Siemens SCALANCE WAM763-1 | ||
Siemens SCALANCE WAM766-1 ECC Firmware | >=1.1.0 | |
Siemens Scalance WAM766-1 6GHz | ||
Siemens Scalance WUM763-1 | >=1.1.0 | |
Siemens Scalance WUM763-1 Firmware | ||
Siemens Scalance WUM766-1 6GHz Firmware | >=1.1.0 | |
Siemens SCALANCE WUM766-1 Firmware | ||
Siemens SCALANCE WAM766-1 ECC Firmware | >=1.1.0 | |
Siemens Scalance WAM766-1 6GHz | ||
All of | ||
Siemens Ruggedcom RM1224 LTE (4G) NAM | <7.1.2 | |
Siemens Ruggedcom RM1224 LTE(4G) EU | ||
All of | ||
siemens scalance m804pb firmware | <7.1.2 | |
Siemens SCALANCE M804PB | ||
All of | ||
Siemens SCALANCE M812-1 | <7.1.2 | |
Siemens SCALANCE M812-1 | ||
All of | ||
Siemens SCALANCE M816-1 (Annex A) | <7.1.2 | |
siemens scalance m816-1 | ||
All of | ||
siemens scalance m826-2 firmware | <7.1.2 | |
siemens scalance m826-2 | ||
All of | ||
siemens scalance m874-2 firmware | <7.1.2 | |
siemens scalance m874-2 | ||
All of | ||
siemens scalance m874-3 firmware | <7.1.2 | |
Siemens SCALANCE M874-3 | ||
All of | ||
siemens scalance m876-3 firmware | <7.1.2 | |
siemens scalance m876-3 | ||
All of | ||
siemens scalance m876-4 firmware | <7.1.2 | |
Siemens SCALANCE M876-4 (EU) Firmware | ||
All of | ||
Siemens Scalance MUM853-1 Firmware | <7.1.2 | |
Siemens Scalance MUM853-1 Firmware | ||
All of | ||
Siemens SCALANCE MUM856-1 (EU) Firmware | <7.1.2 | |
Siemens SCALANCE MUM856-1 | ||
All of | ||
Siemens Scalance S615 Firmware | <7.1.2 | |
Siemens SCALANCE S615 firmware | ||
All of | ||
Siemens Scalance WAM763-1 | >=1.1.0 | |
Siemens SCALANCE WAM763-1 | ||
All of | ||
Siemens SCALANCE WAM766-1 ECC Firmware | >=1.1.0 | |
Siemens Scalance WAM766-1 6GHz | ||
All of | ||
Siemens Scalance WUM763-1 | >=1.1.0 | |
Siemens Scalance WUM763-1 Firmware | ||
All of | ||
Siemens Scalance WUM766-1 6GHz Firmware | >=1.1.0 | |
Siemens SCALANCE WUM766-1 Firmware | ||
All of | ||
Siemens SCALANCE WAM766-1 ECC Firmware | >=1.1.0 | |
Siemens Scalance WAM766-1 6GHz |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31766 is a vulnerability identified in RUGGEDCOM RM1224 LTE(4G) EU (All versions < V7.1.2), RUGGEDCOM RM1224 LTE(4G) NAM (All versions < V7.1.2), SCALANCE M804PB (All versions < V7.1.2), SCALANCE M812-1 ADSL-Router (Annex A) (All versions < V7.1.2), SCALANCE M812-1 ADSL-Router (Annex B) (All versions < V7.1.2).
CVE-2022-31766 has a severity rating of 8.6 (High).
CVE-2022-31766 affects RUGGEDCOM RM1224 LTE(4G) EU (All versions < V7.1.2), RUGGEDCOM RM1224 LTE(4G) NAM (All versions < V7.1.2), SCALANCE M804PB (All versions < V7.1.2), SCALANCE M812-1 ADSL-Router (Annex A) (All versions < V7.1.2), SCALANCE M812-1 ADSL-Router (Annex B) (All versions < V7.1.2).
To fix CVE-2022-31766, update the affected software versions to V7.1.2 or higher.
You can find more information about CVE-2022-31766 in the [Siemens ProductCERT advisory](https://cert-portal.siemens.com/productcert/pdf/ssa-697140.pdf).