CVE-2022-46353
Published: Dec 13, 2022
Modified: Apr 22, 2025
Description
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of affected devices calculates session ids and nonces in an insecure manner. This could allow an unauthenticated remote attacker to brute-force session ids and hijack existing sessions.
| Vendor | Product | Versions |
|---|---|---|
Siemens | SCALANCE X204RNA (HSR) | affected All versions < V3.2.7 |
Siemens | SCALANCE X204RNA (PRP) | affected All versions < V3.2.7 |
Siemens | SCALANCE X204RNA EEC (HSR) | affected All versions < V3.2.7 |
Siemens | SCALANCE X204RNA EEC (PRP) | affected All versions < V3.2.7 |
Siemens | SCALANCE X204RNA EEC (PRP/HSR) | affected All versions < V3.2.7 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now