cvelist/2023/44xxx/CVE-2023-44317.json
2023-12-12 12:00:36 +00:00

1055 lines
52 KiB
JSON

{
"data_version": "4.0",
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2023-44317",
"ASSIGNER": "productcert@siemens.com",
"STATE": "PUBLIC"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU, RUGGEDCOM RM1224 LTE(4G) NAM, SCALANCE M804PB, SCALANCE M812-1 ADSL-Router (Annex A), SCALANCE M812-1 ADSL-Router (Annex B), SCALANCE M816-1 ADSL-Router (Annex A), SCALANCE M816-1 ADSL-Router (Annex B), SCALANCE M826-2 SHDSL-Router, SCALANCE M874-2, SCALANCE M874-3, SCALANCE M876-3 (EVDO), SCALANCE M876-3 (ROK), SCALANCE M876-4, SCALANCE M876-4 (EU), SCALANCE M876-4 (NAM), SCALANCE MUM853-1 (EU), SCALANCE MUM856-1 (EU), SCALANCE MUM856-1 (RoW), SCALANCE S615, SCALANCE S615 EEC, SCALANCE XB205-3 (SC, PN), SCALANCE XB205-3 (ST, E/IP), SCALANCE XB205-3 (ST, E/IP), SCALANCE XB205-3 (ST, PN), SCALANCE XB205-3LD (SC, E/IP), SCALANCE XB205-3LD (SC, PN), SCALANCE XB208 (E/IP), SCALANCE XB208 (PN), SCALANCE XB213-3 (SC, E/IP), SCALANCE XB213-3 (SC, PN), SCALANCE XB213-3 (ST, E/IP), SCALANCE XB213-3 (ST, PN), SCALANCE XB213-3LD (SC, E/IP), SCALANCE XB213-3LD (SC, PN), SCALANCE XB216 (E/IP), SCALANCE XB216 (PN), SCALANCE XC206-2 (SC), SCALANCE XC206-2 (ST/BFOC), SCALANCE XC206-2G PoE, SCALANCE XC206-2G PoE (54 V DC), SCALANCE XC206-2G PoE EEC (54 V DC), SCALANCE XC206-2SFP, SCALANCE XC206-2SFP EEC, SCALANCE XC206-2SFP G, SCALANCE XC206-2SFP G (EIP DEF.), SCALANCE XC206-2SFP G EEC, SCALANCE XC208, SCALANCE XC208EEC, SCALANCE XC208G, SCALANCE XC208G (EIP def.), SCALANCE XC208G EEC, SCALANCE XC208G PoE, SCALANCE XC208G PoE (54 V DC), SCALANCE XC216, SCALANCE XC216-3G PoE, SCALANCE XC216-3G PoE (54 V DC), SCALANCE XC216-4C, SCALANCE XC216-4C G, SCALANCE XC216-4C G (EIP Def.), SCALANCE XC216-4C G EEC, SCALANCE XC216EEC, SCALANCE XC224, SCALANCE XC224-4C G, SCALANCE XC224-4C G (EIP Def.), SCALANCE XC224-4C G EEC, SCALANCE XF204, SCALANCE XF204 DNA, SCALANCE XF204-2BA, SCALANCE XF204-2BA DNA, SCALANCE XP208, SCALANCE XP208 (Ethernet/IP), SCALANCE XP208EEC, SCALANCE XP208PoE EEC, SCALANCE XP216, SCALANCE XP216 (Ethernet/IP), SCALANCE XP216EEC, SCALANCE XP216POE EEC, SCALANCE XR324WG (24 x FE, AC 230V), SCALANCE XR324WG (24 X FE, DC 24V), SCALANCE XR326-2C PoE WG, SCALANCE XR326-2C PoE WG (without UL), SCALANCE XR328-4C WG (24XFE, 4XGE, 24V), SCALANCE XR328-4C WG (24xFE, 4xGE,DC24V), SCALANCE XR328-4C WG (24xFE,4xGE,AC230V), SCALANCE XR328-4C WG (24xFE,4xGE,AC230V), SCALANCE XR328-4C WG (28xGE, AC 230V), SCALANCE XR328-4C WG (28xGE, DC 24V), SIPLUS NET SCALANCE XC206-2, SIPLUS NET SCALANCE XC206-2SFP, SIPLUS NET SCALANCE XC208, SIPLUS NET SCALANCE XC216-4C. Affected products do not properly validate the content of uploaded X509 certificates which could allow an attacker with administrative privileges to execute arbitrary code on the device."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-349: Acceptance of Extraneous Untrusted Data With Trusted Data",
"cweId": "CWE-349"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Siemens",
"product": {
"product_data": [
{
"product_name": "RUGGEDCOM RM1224 LTE(4G) EU",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "RUGGEDCOM RM1224 LTE(4G) NAM",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE M804PB",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE M812-1 ADSL-Router (Annex A)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE M812-1 ADSL-Router (Annex B)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE M816-1 ADSL-Router (Annex A)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE M816-1 ADSL-Router (Annex B)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE M826-2 SHDSL-Router",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE M874-2",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE M874-3",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE M876-3 (EVDO)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE M876-3 (ROK)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE M876-4",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE M876-4 (EU)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE M876-4 (NAM)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE MUM853-1 (EU)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE MUM856-1 (EU)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE MUM856-1 (RoW)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE S615",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE S615 EEC",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V7.2.2"
}
]
}
},
{
"product_name": "SCALANCE XB205-3 (SC, PN)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XB205-3 (ST, E/IP)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
},
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XB205-3 (ST, PN)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XB205-3LD (SC, E/IP)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XB205-3LD (SC, PN)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XB208 (E/IP)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XB208 (PN)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XB213-3 (SC, E/IP)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XB213-3 (SC, PN)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XB213-3 (ST, E/IP)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XB213-3 (ST, PN)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XB213-3LD (SC, E/IP)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XB213-3LD (SC, PN)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XB216 (E/IP)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XB216 (PN)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC206-2 (SC)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC206-2 (ST/BFOC)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC206-2G PoE",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC206-2G PoE (54 V DC)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC206-2G PoE EEC (54 V DC)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC206-2SFP",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC206-2SFP EEC",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC206-2SFP G",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC206-2SFP G (EIP DEF.)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC206-2SFP G EEC",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC208",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC208EEC",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC208G",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC208G (EIP def.)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC208G EEC",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC208G PoE",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC208G PoE (54 V DC)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC216",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC216-3G PoE",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC216-3G PoE (54 V DC)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC216-4C",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC216-4C G",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC216-4C G (EIP Def.)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC216-4C G EEC",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC216EEC",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC224",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC224-4C G",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC224-4C G (EIP Def.)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XC224-4C G EEC",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XF204",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XF204 DNA",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XF204-2BA",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XF204-2BA DNA",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XP208",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XP208 (Ethernet/IP)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XP208EEC",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XP208PoE EEC",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XP216",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XP216 (Ethernet/IP)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XP216EEC",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XP216POE EEC",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XR324WG (24 x FE, AC 230V)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XR324WG (24 X FE, DC 24V)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XR326-2C PoE WG",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XR326-2C PoE WG (without UL)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XR328-4C WG (24XFE, 4XGE, 24V)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XR328-4C WG (24xFE, 4xGE,DC24V)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XR328-4C WG (24xFE,4xGE,AC230V)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
},
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XR328-4C WG (28xGE, AC 230V)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SCALANCE XR328-4C WG (28xGE, DC 24V)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SIPLUS NET SCALANCE XC206-2",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SIPLUS NET SCALANCE XC206-2SFP",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SIPLUS NET SCALANCE XC208",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
},
{
"product_name": "SIPLUS NET SCALANCE XC216-4C",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All versions < V4.5"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-699386.pdf",
"refsource": "MISC",
"name": "https://cert-portal.siemens.com/productcert/pdf/ssa-699386.pdf"
},
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-068047.pdf",
"refsource": "MISC",
"name": "https://cert-portal.siemens.com/productcert/pdf/ssa-068047.pdf"
}
]
},
"impact": {
"cvss": [
{
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C",
"baseScore": 7.2,
"baseSeverity": "HIGH"
}
]
}
}