CVE-2025-24499
Published: Feb 11, 2025
Modified: Feb 12, 2025
CVSS v3.1
7.2
Description
A vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) (All versions < V3.0.0), SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0) (All versions < V3.0.0), SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0) (All versions < V3.0.0), SCALANCE WAM766-1 (6GK5766-1GE00-7DA0) (All versions < V3.0.0), SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0) (All versions < V3.0.0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0) (All versions < V3.0.0), SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0) (All versions < V3.0.0), SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0) (All versions < V3.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0) (All versions < V3.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0) (All versions < V3.0.0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0) (All versions < V3.0.0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0) (All versions < V3.0.0), SCALANCE WUM766-1 (6GK5766-1GE00-3DA0) (All versions < V3.0.0), SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0) (All versions < V3.0.0), SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0) (All versions < V3.0.0). Affected devices do not properly validate input while loading the configuration files. This could allow an authenticated remote attacker to execute arbitrary shell commands on the device.
| Vendor | Product | Versions |
|---|---|---|
Siemens | SCALANCE WAB762-1 | affected 0 - < V3.0.0 |
Siemens | SCALANCE WAM763-1 | affected 0 - < V3.0.0 |
Siemens | SCALANCE WAM763-1 (ME) | affected 0 - < V3.0.0 |
Siemens | SCALANCE WAM763-1 (US) | affected 0 - < V3.0.0 |
Siemens | SCALANCE WAM766-1 | affected 0 - < V3.0.0 |
Siemens | SCALANCE WAM766-1 (ME) | affected 0 - < V3.0.0 |
Siemens | SCALANCE WAM766-1 (US) | affected 0 - < V3.0.0 |
Siemens | SCALANCE WAM766-1 EEC | affected 0 - < V3.0.0 |
Siemens | SCALANCE WAM766-1 EEC (ME) | affected 0 - < V3.0.0 |
Siemens | SCALANCE WAM766-1 EEC (US) | affected 0 - < V3.0.0 |
Siemens | SCALANCE WUB762-1 | affected 0 - < V3.0.0 |
Siemens | SCALANCE WUB762-1 iFeatures | affected 0 - < V3.0.0 |
Siemens | SCALANCE WUM763-1 | affected 0 - < V3.0.0 |
Siemens | SCALANCE WUM763-1 | affected 0 - < V3.0.0 |
Siemens | SCALANCE WUM763-1 (US) | affected 0 - < V3.0.0 |
Siemens | SCALANCE WUM763-1 (US) | affected 0 - < V3.0.0 |
Siemens | SCALANCE WUM766-1 | affected 0 - < V3.0.0 |
Siemens | SCALANCE WUM766-1 (ME) | affected 0 - < V3.0.0 |
Siemens | SCALANCE WUM766-1 (USA) | affected 0 - < V3.0.0 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now