MEDIUM · 5.9

CVE-2020-28395

A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do no...

Vulnerability Description

A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do not create a new unique private key after factory reset. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
SiemensScalance Xr324-12M Firmware< 4.1.0
SiemensScalance Xr324-12M-
SiemensScalance Xr324-12M Ts Firmware< 4.1.0
SiemensScalance Xr324-12M Ts-
SiemensScalance Xr324-4M Eec Firmware< 4.1.0
SiemensScalance Xr324-4M Eec-
SiemensScalance Xr324-4M Poe Firmware< 4.1.0
SiemensScalance Xr324-4M Poe-
SiemensScalance Xr324-4M Poe Ts Firmware< 4.1.0
SiemensScalance Xr324-4M Poe Ts-
SiemensScalance Xr324Wg Firmware< 4.1.0
SiemensScalance Xr324Wg-
SiemensScalance Xr326-2C Poe Wg Firmware< 4.1.0
SiemensScalance Xr326-2C Poe Wg-
SiemensScalance Xr328-4C Wg Firmware< 4.1.0
SiemensScalance Xr328-4C Wg-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-28395?

CVE-2020-28395 is a vulnerability with a CVSS score of 5.9 (MEDIUM). A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do no...

How severe is CVE-2020-28395?

CVE-2020-28395 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-28395?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Scalance Xr324-12M Firmware, Siemens Scalance Xr324-12M, Siemens Scalance Xr324-12M Ts Firmware, Siemens Scalance Xr324-12M Ts, Siemens Scalance Xr324-4M Eec Firmware.