« Volver al listado

CVE-2022-46354

Estado: ModificadaMedia (5.3)—

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of an affected device is missing specific security headers. This could allow an remote attacker to extract confidential session information under certain circumstances.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-46354",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-46354",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-22T14:40:24.640259Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "productcert@siemens.com",
      "affectedData": [
        {
          "vendor": "Siemens",
          "product": "SCALANCE X204RNA (HSR)",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V3.2.7"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "SCALANCE X204RNA (PRP)",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V3.2.7"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "SCALANCE X204RNA EEC (HSR)",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V3.2.7"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "SCALANCE X204RNA EEC (PRP)",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V3.2.7"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "SCALANCE X204RNA EEC (PRP/HSR)",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V3.2.7"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-12-13T16:15:25.917",
  "references": [
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-363821.pdf",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "productcert@siemens.com"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-363821.pdf",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "productcert@siemens.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of an affected device is missing specific security headers. This could allow an remote attacker to extract confidential session information under certain circumstances."
    },
    {
      "lang": "es",
      "value": "Se ha identificado una vulnerabilidad en \nSCALANCE X204RNA (HSR) (Todas las versiones &lt; V3.2.7), \nSCALANCE X204RNA (PRP) (Todas las versiones &lt; V3.2.7), \nSCALANCE X204RNA EEC (HSR) (Todas las versiones &lt; V3.2.7 ), \nSCALANCE X204RNA EEC (PRP) (todas las versiones &lt; V3.2.7), \nSCALANCE X204RNA EEC (PRP/HSR) (todas las versiones &lt; V3.2.7). \nAl servidor web de un dispositivo afectado le faltan encabezados de seguridad específicos. Esto podría permitir que un atacante remoto extraiga información confidencial de la sesión en determinadas circunstancias."
    }
  ],
  "lastModified": "2026-06-17T05:11:36.310",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:6gk5204-0ba00-2mb2_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77A54E43-E9A5-49CF-BA3C-E6878C2C713F",
              "versionEndExcluding": "3.2.7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:6gk5204-0ba00-2mb2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AF6E5E68-552D-40C1-A4AB-605D0F21688F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:6gk5204-0ba00-2kb2_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE326B9F-A613-46B5-A20D-BE9D41A80857",
              "versionEndExcluding": "3.2.7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:6gk5204-0ba00-2kb2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7B61CA05-D98E-4BD6-BE78-58574B2DE5CA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:6gk5204-0bs00-2na3_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6FCF31E-22CA-4038-AC27-BAEA752A718D",
              "versionEndExcluding": "3.2.7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:6gk5204-0bs00-2na3:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "28B98E8F-0E32-4BA4-8237-055BDB25C1B3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:6gk5204-0bs00-3la3_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7EA94F5-1AB0-4BE2-810A-46B840070856",
              "versionEndExcluding": "3.2.7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:6gk5204-0bs00-3la3:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D92CFF31-E138-49D0-A9FF-A91E7342AEFC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:6gk5204-0bs00-3pa3_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06CBD11B-3671-425B-89EB-4B9677B3316B",
              "versionEndExcluding": "3.2.7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:6gk5204-0bs00-3pa3:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1572F77B-98B7-44D9-9DF9-9EC56CD6E571"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "productcert@siemens.com"
}