First published: Tue Oct 11 2022(Updated: )
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (All versions < V7.1.2), RUGGEDCOM RM1224 LTE(4G) NAM (All versions < V7.1.2), SCALANCE M804PB (All versions < V7.1.2), SCALANCE M812-1 ADSL-Router (Annex A) (All versions < V7.1.2), SCALANCE M812-1 ADSL-Router (Annex B) (All versions < V7.1.2), SCALANCE M816-1 ADSL-Router (Annex A) (All versions < V7.1.2), SCALANCE M816-1 ADSL-Router (Annex B) (All versions < V7.1.2), SCALANCE M826-2 SHDSL-Router (All versions < V7.1.2), SCALANCE M874-2 (All versions < V7.1.2), SCALANCE M874-3 (All versions < V7.1.2), SCALANCE M876-3 (EVDO) (All versions < V7.1.2), SCALANCE M876-3 (ROK) (All versions < V7.1.2), SCALANCE M876-4 (All versions < V7.1.2), SCALANCE M876-4 (EU) (All versions < V7.1.2), SCALANCE M876-4 (NAM) (All versions < V7.1.2), SCALANCE MUM853-1 (EU) (All versions < V7.1.2), SCALANCE MUM856-1 (EU) (All versions < V7.1.2), SCALANCE MUM856-1 (RoW) (All versions < V7.1.2), SCALANCE S615 (All versions < V7.1.2), SCALANCE S615 EEC (All versions < V7.1.2), SCALANCE WAM763-1 (All versions >= V1.1.0 < V2.0), SCALANCE WAM766-1 (EU) (All versions >= V1.1.0 < V2.0), SCALANCE WAM766-1 (US) (All versions >= V1.1.0 < V2.0), SCALANCE WAM766-1 EEC (EU) (All versions >= V1.1.0 < V2.0), SCALANCE WAM766-1 EEC (US) (All versions >= V1.1.0 < V2.0), SCALANCE WUM763-1 (All versions >= V1.1.0 < V2.0), SCALANCE WUM763-1 (All versions >= V1.1.0 < V2.0), SCALANCE WUM766-1 (EU) (All versions >= V1.1.0 < V2.0), SCALANCE WUM766-1 (US) (All versions >= V1.1.0 < V2.0). Affected devices with TCP Event service enabled do not properly handle malformed packets. This could allow an unauthenticated remote attacker to cause a denial of service condition and reboot the device thus possibly affecting other network resources.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Ruggedcom Rm1224 Firmware | <7.1.2 | |
Siemens RUGGEDCOM RM1224 | ||
Siemens Scalance M804pb Firmware | <7.1.2 | |
Siemens Scalance M804pb | ||
Siemens Scalance M812-1 Firmware | <7.1.2 | |
Siemens Scalance M812-1 | ||
Siemens Scalance M816-1 Firmware | <7.1.2 | |
Siemens Scalance M816-1 | ||
Siemens Scalance M826-2 Firmware | <7.1.2 | |
Siemens Scalance M826-2 | ||
Siemens Scalance M874-2 Firmware | <7.1.2 | |
Siemens Scalance M874-2 | ||
Siemens Scalance M874-3 Firmware | <7.1.2 | |
Siemens Scalance M874-3 | ||
Siemens Scalance M876-3 Firmware | <7.1.2 | |
Siemens Scalance M876-3 | ||
Siemens Scalance M876-4 Firmware | <7.1.2 | |
Siemens Scalance M876-4 | ||
Siemens Scalance Mum853-1 Firmware | <7.1.2 | |
Siemens Scalance Mum853-1 | ||
Siemens Scalance Mum856-1 Firmware | <7.1.2 | |
Siemens Scalance Mum856-1 | ||
Siemens Scalance S615 Firmware | <7.1.2 | |
Siemens SCALANCE S615 | ||
Siemens Scalance Wam763-1 Firmware | >=1.1.0 | |
Siemens Scalance Wam763-1 | ||
Siemens Scalance Wam766-1 Firmware | >=1.1.0 | |
Siemens Scalance Wam766-1 | ||
Siemens Scalance Wum763-1 Firmware | >=1.1.0 | |
Siemens Scalance Wum763-1 | ||
Siemens Scalance Wum766-1 Firmware | >=1.1.0 | |
Siemens Scalance Wum766-1 | ||
Siemens Scalance Wam766-1 Firmware | >=1.1.0 | |
Siemens Scalance Wam766-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31766 is a vulnerability identified in RUGGEDCOM RM1224 LTE(4G) EU (All versions < V7.1.2), RUGGEDCOM RM1224 LTE(4G) NAM (All versions < V7.1.2), SCALANCE M804PB (All versions < V7.1.2), SCALANCE M812-1 ADSL-Router (Annex A) (All versions < V7.1.2), SCALANCE M812-1 ADSL-Router (Annex B) (All versions < V7.1.2).
CVE-2022-31766 has a severity rating of 8.6 (High).
CVE-2022-31766 affects RUGGEDCOM RM1224 LTE(4G) EU (All versions < V7.1.2), RUGGEDCOM RM1224 LTE(4G) NAM (All versions < V7.1.2), SCALANCE M804PB (All versions < V7.1.2), SCALANCE M812-1 ADSL-Router (Annex A) (All versions < V7.1.2), SCALANCE M812-1 ADSL-Router (Annex B) (All versions < V7.1.2).
To fix CVE-2022-31766, update the affected software versions to V7.1.2 or higher.
You can find more information about CVE-2022-31766 in the [Siemens ProductCERT advisory](https://cert-portal.siemens.com/productcert/pdf/ssa-697140.pdf).