CVE-2022-46353: Critical severity siemens 6gk5204-0ba00-2gf2 vulnerability
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of affected devices calculates session ids and nonces in an insecure manner. This could allow an unauthenticated remote attacker to brute-force session ids and hijack existing sessions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-46353?
CVE-2022-46353 has been classified as a moderate severity vulnerability.
How do I fix CVE-2022-46353?
To fix CVE-2022-46353, upgrade affected SCALANCE X204RNA devices to version 3.2.7 or later.
Which versions of SCALANCE X204RNA are affected by CVE-2022-46353?
All versions of SCALANCE X204RNA prior to version 3.2.7 are affected by CVE-2022-46353.
What types of devices are impacted by CVE-2022-46353?
CVE-2022-46353 impacts SCALANCE X204RNA devices configured for HSR and PRP redundancy protocols.
Is there a workaround for CVE-2022-46353?
There is no known workaround for CVE-2022-46353; upgrading to the latest firmware is recommended.