Vulnerability Description
Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of service condition for the duration of the attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Scalance M-800 Firmware | All versions |
| Siemens | Scalance M-800 | - |
| Siemens | Scalance S615 Firmware | All versions |
| Siemens | Scalance S615 | - |
| Siemens | Scalance W700 Ieee 802.11Ax Firmware | All versions |
| Siemens | Scalance W700 Ieee 802.11Ax | - |
| Siemens | Scalance W700 Ieee 802.11N Firmware | All versions |
| Siemens | Scalance W700 Ieee 802.11N | - |
| Siemens | Scalance W700 Ieee 802.11Ac Firmware | All versions |
| Siemens | Scalance W700 Ieee 802.11Ac | - |
| Siemens | Scalance Xb-200 Firmware | All versions |
| Siemens | Scalance Xb-200 | - |
| Siemens | Scalance Xb205-3 Firmware | All versions |
| Siemens | Scalance Xb205-3 | - |
| Siemens | Scalance Xb205-3Ld Firmware | All versions |
| Siemens | Scalance Xb205-3Ld | - |
| Siemens | Scalance Xb208 Firmware | All versions |
| Siemens | Scalance Xb208 | - |
| Siemens | Scalance Xb213-3 Firmware | All versions |
| Siemens | Scalance Xb213-3 | - |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/html/ssa-019200.html
- https://cert-portal.siemens.com/productcert/html/ssa-710008.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-710008.pdfMitigationVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-710008.pdfMitigationVendor Advisory
FAQ
What is CVE-2022-36324?
CVE-2022-36324 is a vulnerability with a CVSS score of 7.5 (HIGH). Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of se...
How severe is CVE-2022-36324?
CVE-2022-36324 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-36324?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Scalance M-800 Firmware, Siemens Scalance M-800, Siemens Scalance S615 Firmware, Siemens Scalance S615, Siemens Scalance W700 Ieee 802.11Ax Firmware.