CVE-2022-46144: High severity siemens 6gk5622-2gs00-2ac2 vulnerability
A vulnerability has been identified in SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (All versions < V2.3), SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (All versions >= V2.3 < V3.0), SCALANCE SC626-2C (6GK5626-2GS00-2AC2) (All versions < V2.3), SCALANCE SC626-2C (6GK5626-2GS00-2AC2) (All versions >= V2.3 < V3.0), SCALANCE SC632-2C (6GK5632-2GS00-2AC2) (All versions < V2.3), SCALANCE SC632-2C (6GK5632-2GS00-2AC2) (All versions >= V2.3 < V3.0), SCALANCE SC636-2C (6GK5636-2GS00-2AC2) (All versions < V2.3), SCALANCE SC636-2C (6GK5636-2GS00-2AC2) (All versions >= V2.3 < V3.0), SCALANCE SC642-2C (6GK5642-2GS00-2AC2) (All versions < V2.3), SCALANCE SC642-2C (6GK5642-2GS00-2AC2) (All versions >= V2.3 < V3.0), SCALANCE SC646-2C (6GK5646-2GS00-2AC2) (All versions < V2.3), SCALANCE SC646-2C (6GK5646-2GS00-2AC2) (All versions >= V2.3 < V3.0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) (All versions < V2.0.0), SCALANCE WAM766-1 (6GK5766-1GE00-7DA0) (All versions < V2.0.0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0) (All versions < V2.0.0), SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0) (All versions < V2.0.0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0) (All versions < V2.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0) (All versions < V2.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0) (All versions < V2.0.0), SCALANCE WUM766-1 (6GK5766-1GE00-3DA0) (All versions < V2.0.0), SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0) (All versions < V2.0.0). Affected devices do not properly process CLI commands after a user forcefully quitted the SSH connection. This could allow an authenticated attacker to make the CLI via SSH or serial interface irresponsive.
Other sources
A vulnerability has been identified in SCALANCE SC622-2C (All versions < V2.3), SCALANCE SC622-2C (All versions >= V2.3 < V3.0), SCALANCE SC626-2C (All versions < V2.3), SCALANCE SC626-2C (All versions >= V2.3 < V3.0), SCALANCE SC632-2C (All versions < V2.3), SCALANCE SC632-2C (All versions >= V2.3 < V3.0), SCALANCE SC636-2C (All versions < V2.3), SCALANCE SC636-2C (All versions >= V2.3 < V3.0), SCALANCE SC642-2C (All versions < V2.3), SCALANCE SC642-2C (All versions >= V2.3 < V3.0), SCALANCE SC646-2C (All versions < V2.3), SCALANCE SC646-2C (All versions >= V2.3 < V3.0). Affected devices do not properly process CLI commands after a user forcefully quitted the SSH connection. This could allow an authenticated attacker to make the CLI via SSH or serial interface irresponsive.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-46144.
What is the severity of CVE-2022-46144?
The severity of CVE-2022-46144 is medium with a CVSS score of 6.5.
Which products are affected by CVE-2022-46144?
The SCALANCE SC622-2C (versions < V2.3), SC626-2C (versions < V2.3), SC632-2C (versions < V2.3), SC5622-2GS00-2AC2 Firmware (versions < V2.3), SC5626-2GS00-2AC2 Firmware (versions < V2.3), SC5632-2GS00-2AC2 Firmware (versions < V2.3), SC5636-2GS00-2AC2 Firmware (versions < V2.3), SC5642-2GS00-2AC2 Firmware (versions < V2.3), and SC5646-2GS00-2AC2 Firmware (versions < V2.3) are affected by CVE-2022-46144.
How can I fix CVE-2022-46144?
To fix CVE-2022-46144, Siemens recommends updating to version V2.3 or higher for SC622-2C, SC626-2C, SC632-2C, SC5622-2GS00-2AC2 Firmware, SC5626-2GS00-2AC2 Firmware, SC5632-2GS00-2AC2 Firmware, SC5636-2GS00-2AC2 Firmware, SC5642-2GS00-2AC2 Firmware, and SC5646-2GS00-2AC2 Firmware.
Where can I find more information about CVE-2022-46144?
You can find more information about CVE-2022-46144 on the Siemens ProductCERT website: [link](https://cert-portal.siemens.com/productcert/pdf/ssa-413565.pdf).