CRITICAL · 9.8

CVE-2020-25226

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5....

Vulnerability Description

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0). The web server of the affected devices contains a vulnerability that may lead to a buffer overflow condition. An attacker could cause this condition on the webserver by sending a specially crafted request. The webserver could stop and not recover anymore.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SiemensScalance X200-4Pirt Firmware< 5.5.0
SiemensScalance X200-4Pirt-
SiemensScalance X201-3Pirt Firmware< 5.5.0
SiemensScalance X201-3Pirt-
SiemensScalance X202-2Irt Firmware< 5.5.0
SiemensScalance X202-2Irt-
SiemensScalance X202-2Pirt Firmware< 5.5.0
SiemensScalance X202-2Pirt-
SiemensScalance X202-2Pirt Siplus Net Firmware< 5.5.0
SiemensScalance X202-2Pirt Siplus Net-
SiemensScalance X204Irt Firmware< 5.5.0
SiemensScalance X204Irt-
SiemensScalance X307-3 FirmwareAll versions
SiemensScalance X307-3-
SiemensScalance X307-3Ld FirmwareAll versions
SiemensScalance X307-3Ld-
SiemensScalance X308-2 FirmwareAll versions
SiemensScalance X308-2-
SiemensScalance X308-2Ld FirmwareAll versions
SiemensScalance X308-2Ld-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-25226?

CVE-2020-25226 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5....

How severe is CVE-2020-25226?

CVE-2020-25226 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-25226?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Scalance X200-4Pirt Firmware, Siemens Scalance X200-4Pirt, Siemens Scalance X201-3Pirt Firmware, Siemens Scalance X201-3Pirt, Siemens Scalance X202-2Irt Firmware.