First published: Wed Oct 23 2024(Updated: )
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices does not authenticate GET requests that execute specific commands (such as `ping`) on operating system level.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Siemens Intermesh 7177 Hybrid 2.0 Subscriber | <8.2.12 | |
Siemens Intermesh 7177 Hybrid 2.0 Subscriber | ||
All of | ||
Siemens Intermesh 7707 Fire Subscriber Firmware | <7.2.12 | |
Siemens Intermesh 7707 Fire Subscriber |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.