2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2022-27481" ,
"sourceIdentifier" : "productcert@siemens.com" ,
"published" : "2022-04-12T09:15:15.150" ,
"lastModified" : "2022-04-19T18:25:04.183" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), SCALANCE W1788-2IA M12 (All versions < V3.0.0). Affected devices do not properly handle resources of ARP requests. This could allow an attacker to cause a race condition that leads to a crash of the entire device."
} ,
{
"lang" : "es" ,
"value" : "Se ha identificado una vulnerabilidad en SCALANCE W1788-1 M12 (todas las versiones anteriores a V3.0.0), SCALANCE W1788-2 EEC M12 (todas las versiones anteriores a V3.0.0), SCALANCE W1788-2 M12 (todas las versiones anteriores a V3.0.0), SCALANCE W1788-2IA M12 (todas las versiones anteriores a V3.0.0). Los dispositivos afectados no manejan correctamente los recursos de las peticiones ARP. Esto podr\u00eda permitir a un atacante causar una condici\u00f3n de carrera que conlleva a un bloqueo de todo el dispositivo"
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" ,
"attackVector" : "ADJACENT_NETWORK" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 5.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 1.6 ,
"impactScore" : 3.6
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:A/AC:M/Au:N/C:N/I:N/A:C" ,
"accessVector" : "ADJACENT_NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "COMPLETE" ,
"baseScore" : 5.7
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 5.5 ,
"impactScore" : 6.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-362"
}
]
} ,
{
"source" : "productcert@siemens.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-362"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_w1788-2ia_m12_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "3.0.0" ,
"matchCriteriaId" : "C2A7EE5C-4FF7-4B6C-AC85-0B992BBB237B"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_w1788-2ia_m12:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D9491822-56EE-4065-B199-040BEE283ED0"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_w1788-2_m12_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "3.0.0" ,
"matchCriteriaId" : "787289C3-1A38-4F3A-856F-5E79B150F14F"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_w1788-2_m12:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D8AA449C-52AE-4286-8BD2-C1A54A1AC64E"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_w1788-2_eec_m12_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "3.0.0" ,
"matchCriteriaId" : "3D981998-87CF-4EF8-9430-F4ACF3214B58"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_w1788-2_eec_m12:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8AE6F9AD-37DB-4067-8BB4-10CDD3AA8E23"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_w1788-1_m12_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "3.0.0" ,
"matchCriteriaId" : "32D25E1B-2C32-483C-B520-8AA7B02162F0"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_w1788-1_m12:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "408600B8-762D-43C9-A259-7163FA9DB788"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-392912.pdf" ,
"source" : "productcert@siemens.com" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
}
]
}