CVE Database
/

CVE-2020-28395

Back to search

CVE-2020-28395

Published: Jan 12, 2021

Modified: Aug 4, 2024

PUBLISHED

Description

A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do not create a new unique private key after factory reset. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic.

VendorProductVersions

Siemens

SCALANCE X-200RNA switch family

affected
All versions < V3.2.7

Siemens

SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants)

affected
All versions < V4.1.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now