MEDIUM · 6.5

CVE-2020-15799

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5....

Vulnerability Description

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0). The vulnerability could allow an unauthenticated attacker to reboot the device over the network by using special urls from integrated web server of the affected products.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
SiemensScalance X200-4Pirt Firmware< 5.5.0
SiemensScalance X200-4Pirt-
SiemensScalance X201-3Pirt Firmware< 5.5.0
SiemensScalance X201-3Pirt-
SiemensScalance X202-2Irt Firmware< 5.5.0
SiemensScalance X202-2Irt-
SiemensScalance X202-2Pirt Firmware< 5.5.0
SiemensScalance X202-2Pirt-
SiemensScalance X202-2Pirt Siplus Net Firmware< 5.5.0
SiemensScalance X202-2Pirt Siplus Net-
SiemensScalance X204Irt Firmware< 5.5.0
SiemensScalance X204Irt-
SiemensScalance X307-3 FirmwareAll versions
SiemensScalance X307-3-
SiemensScalance X307-3Ld FirmwareAll versions
SiemensScalance X307-3Ld-
SiemensScalance X308-2 FirmwareAll versions
SiemensScalance X308-2-
SiemensScalance X308-2Ld FirmwareAll versions
SiemensScalance X308-2Ld-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-15799?

CVE-2020-15799 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5....

How severe is CVE-2020-15799?

CVE-2020-15799 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-15799?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Scalance X200-4Pirt Firmware, Siemens Scalance X200-4Pirt, Siemens Scalance X201-3Pirt Firmware, Siemens Scalance X201-3Pirt, Siemens Scalance X202-2Irt Firmware.