CVE-2022-46355: Infoleak
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The affected products are vulnerable to an "Exposure of Sensitive Information to an Unauthorized Actor" vulnerability by leaking sensitive data in the HTTP Referer.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-46355?
The severity of CVE-2022-46355 is not explicitly stated but it affects multiple versions of Siemens SCALANCE devices.
How do I fix CVE-2022-46355?
To fix CVE-2022-46355, update the affected SCALANCE devices to version 3.2.7 or later.
Which devices are affected by CVE-2022-46355?
CVE-2022-46355 affects all versions of SCALANCE X204RNA devices prior to version 3.2.7.
Is there a patch available for CVE-2022-46355?
Yes, a patch in the form of a firmware update to version 3.2.7 is available to mitigate CVE-2022-46355.
What types of functionality does CVE-2022-46355 impact?
CVE-2022-46355 impacts functionality related to network redundancy protocols in the affected SCALANCE devices.