CRITICAL · 9.1

CVE-2022-36323

Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.

Vulnerability Description

Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.

CVSS Score

9.1

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SiemensScalance M-800 FirmwareAll versions
SiemensScalance M-800-
SiemensScalance S615 FirmwareAll versions
SiemensScalance S615-
SiemensScalance Sc-600 Firmware< 2.3.1
SiemensScalance Sc-600-
SiemensScalance Sc622-2C Firmware< 2.3.1
SiemensScalance Sc622-2C-
SiemensScalance Sc632-2C Firmware< 2.3.1
SiemensScalance Sc632-2C-
SiemensScalance Sc636-2C Firmware< 2.3.1
SiemensScalance Sc636-2C-
SiemensScalance Sc642-2C Firmware< 2.3.1
SiemensScalance Sc642-2C-
SiemensScalance Sc646-2C Firmware< 2.3.1
SiemensScalance Sc646-2C-
SiemensScalance W700 Ieee 802.11Ax FirmwareAll versions
SiemensScalance W700 Ieee 802.11Ax-
SiemensScalance W700 Ieee 802.11N FirmwareAll versions
SiemensScalance W700 Ieee 802.11N-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-36323?

CVE-2022-36323 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.

How severe is CVE-2022-36323?

CVE-2022-36323 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-36323?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Scalance M-800 Firmware, Siemens Scalance M-800, Siemens Scalance S615 Firmware, Siemens Scalance S615, Siemens Scalance Sc-600 Firmware.