CVE-2020-15800

high-risk
Published 2021-01-12

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). The webserver of the affected devices contains a vulnerability that may lead to a heap overflow condition. An attacker could cause this condition on the webserver by sending specially crafted requests. This could stop the webserver temporarily.

Do I need to act?

-
0.68% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10 Critical
NETWORK / LOW complexity

Affected Products (20)

Scalance X200-4Pirt Firmware
Scalance X201-3Pirt Firmware
Scalance X202-2Irt Firmware
Scalance X202-2Pirt Firmware
Scalance X202-2Pirt Siplus Net Firmware
Scalance X204Irt Firmware
Scalance X307-3 Firmware
Scalance X307-3Ld Firmware
Scalance X308-2 Firmware
Scalance X308-2Ld Firmware
Scalance X308-2Lh Firmware
Scalance X308-2Lh\+ Firmware
Scalance X308-2M Firmware
Scalance X308-2M Ts Firmware
Scalance X310 Firmware
Scalance X310Fe Firmware
Scalance X320-1Fe Firmware
Scalance X320-3Ldfe Firmware
Scalance Xb205-3 Firmware
Scalance Xb205-3Ld Firmware

Affected Vendors

61
/ 100
high-risk
Severity 32/34 · Critical
Exploitability 2/34 · Minimal
Exposure 27/34 · High