Vulnerability Description
A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do not create a new unique private key after factory reset. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Scalance Xr324-12M Firmware | < 4.1.0 |
| Siemens | Scalance Xr324-12M | - |
| Siemens | Scalance Xr324-12M Ts Firmware | < 4.1.0 |
| Siemens | Scalance Xr324-12M Ts | - |
| Siemens | Scalance Xr324-4M Eec Firmware | < 4.1.0 |
| Siemens | Scalance Xr324-4M Eec | - |
| Siemens | Scalance Xr324-4M Poe Firmware | < 4.1.0 |
| Siemens | Scalance Xr324-4M Poe | - |
| Siemens | Scalance Xr324-4M Poe Ts Firmware | < 4.1.0 |
| Siemens | Scalance Xr324-4M Poe Ts | - |
| Siemens | Scalance Xr324Wg Firmware | < 4.1.0 |
| Siemens | Scalance Xr324Wg | - |
| Siemens | Scalance Xr326-2C Poe Wg Firmware | < 4.1.0 |
| Siemens | Scalance Xr326-2C Poe Wg | - |
| Siemens | Scalance Xr328-4C Wg Firmware | < 4.1.0 |
| Siemens | Scalance Xr328-4C Wg | - |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-274900.pdfVendor Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-012-02Third Party AdvisoryUS Government ResourceVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-274900.pdfVendor Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-012-02Third Party AdvisoryUS Government ResourceVendor Advisory
FAQ
What is CVE-2020-28395?
CVE-2020-28395 is a vulnerability with a CVSS score of 5.9 (MEDIUM). A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do no...
How severe is CVE-2020-28395?
CVE-2020-28395 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-28395?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Scalance Xr324-12M Firmware, Siemens Scalance Xr324-12M, Siemens Scalance Xr324-12M Ts Firmware, Siemens Scalance Xr324-12M Ts, Siemens Scalance Xr324-4M Eec Firmware.