VendorsSiemensscalance_xc208_poe_firmwareall versions
Vulnerabilities

Siemens SCALANCE XC208 POE Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2022-46140
Affected devices use a weak encryption scheme to encrypt the debug zip file. This could allow an authenticated attacker to decrypt the contents of the file and retrieve debug information about the system.
Published 2022-12-13 · Modified
7.1EPSS 0.002
CVE-2022-46142
Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords.
Published 2022-12-13 · Modified
5.7EPSS 0.003
CVE-2022-46143
Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an uninitialized buffer that potentially contains previously allocated data.
Published 2022-12-13 · Modified
5.1EPSS 0.007