Publication Date: 2022-04-12
Last Update: 2022-04-12
Current Version: V1.0
CVSS v3.1 Base Score: 9.6

Affected Product and Versions Remediation
SCALANCE X302-7 EEC (2x 24V) (6GK5302-7GD00-2EA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X302-7 EEC (2x 24V, coated) (6GK5302-7GD00-2GA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X302-7 EEC (2x 230V) (6GK5302-7GD00-4EA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X302-7 EEC (2x 230V, coated) (6GK5302-7GD00-4GA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X302-7 EEC (24V) (6GK5302-7GD00-1EA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X302-7 EEC (24V, coated) (6GK5302-7GD00-1GA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X302-7 EEC (230V) (6GK5302-7GD00-3EA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X302-7 EEC (230V, coated) (6GK5302-7GD00-3GA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X304-2FE (6GK5304-2BD00-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X306-1LD FE (6GK5306-1BF00-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X307-2 EEC (2x 24V) (6GK5307-2FD00-2EA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X307-2 EEC (2x 24V, coated) (6GK5307-2FD00-2GA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X307-2 EEC (2x 230V) (6GK5307-2FD00-4EA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X307-2 EEC (2x 230V, coated) (6GK5307-2FD00-4GA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X307-2 EEC (24V) (6GK5307-2FD00-1EA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X307-2 EEC (24V, coated) (6GK5307-2FD00-1GA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X307-2 EEC (230V) (6GK5307-2FD00-3EA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X307-2 EEC (230V, coated) (6GK5307-2FD00-3GA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X307-3 (6GK5307-3BL00-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X307-3 (6GK5307-3BL10-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X307-3LD (6GK5307-3BM00-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X307-3LD (6GK5307-3BM10-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X308-2 (6GK5308-2FL00-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X308-2 (6GK5308-2FL10-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X308-2LD (6GK5308-2FM00-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X308-2LD (6GK5308-2FM10-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X308-2LH (6GK5308-2FN00-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X308-2LH (6GK5308-2FN10-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X308-2LH+ (6GK5308-2FP00-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X308-2LH+ (6GK5308-2FP10-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X308-2M (6GK5308-2GG00-2AA2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X308-2M (6GK5308-2GG10-2AA2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X308-2M PoE (6GK5308-2QG00-2AA2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X308-2M PoE (6GK5308-2QG10-2AA2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X308-2M TS (6GK5308-2GG00-2CA2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X308-2M TS (6GK5308-2GG10-2CA2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X310 (6GK5310-0FA00-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X310 (6GK5310-0FA10-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X310FE (6GK5310-0BA00-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X310FE (6GK5310-0BA10-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X320-1 FE (6GK5320-1BD00-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X320-1-2LD FE (6GK5320-3BF00-2AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE X408-2 (6GK5408-2FD00-2AA2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M EEC (2x 24V, ports on front) (6GK5324-4GG00-2ER2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M EEC (2x 24V, ports on front) (6GK5324-4GG10-2ER2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M EEC (2x 24V, ports on rear) (6GK5324-4GG00-2JR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M EEC (2x 24V, ports on rear) (6GK5324-4GG10-2JR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front) (6GK5324-4GG00-4ER2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front) (6GK5324-4GG10-4ER2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG00-4JR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG10-4JR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M EEC (24V, ports on front) (6GK5324-4GG00-1ER2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M EEC (24V, ports on front) (6GK5324-4GG10-1ER2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M EEC (24V, ports on rear) (6GK5324-4GG00-1JR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M EEC (24V, ports on rear) (6GK5324-4GG10-1JR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front) (6GK5324-4GG00-3ER2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front) (6GK5324-4GG10-3ER2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG00-3JR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG10-3JR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M PoE (24V, ports on front) (6GK5324-4QG00-1AR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M PoE (24V, ports on rear) (6GK5324-4QG00-1HR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M PoE (230V, ports on front) (6GK5324-4QG00-3AR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M PoE (230V, ports on rear) (6GK5324-4QG00-3HR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-4M PoE TS (24V, ports on front) (6GK5324-4QG00-1CR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-12M (24V, ports on front) (6GK5324-0GG00-1AR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-12M (24V, ports on front) (6GK5324-0GG10-1AR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-12M (24V, ports on rear) (6GK5324-0GG00-1HR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-12M (24V, ports on rear) (6GK5324-0GG10-1HR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-12M (230V, ports on front) (6GK5324-0GG00-3AR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-12M (230V, ports on front) (6GK5324-0GG10-3AR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-12M (230V, ports on rear) (6GK5324-0GG00-3HR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-12M (230V, ports on rear) (6GK5324-0GG10-3HR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-12M TS (24V) (6GK5324-0GG00-1CR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SCALANCE XR324-12M TS (24V) (6GK5324-0GG10-1CR2):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations
SIPLUS NET SCALANCE X308-2 (6AG1308-2FL10-4AA3):
All versions < V4.1.4
Update to V4.1.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109808359/
See further recommendations from section Workarounds and Mitigations

CVSS v3.1 Base Score 8.2
CVSS Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-20: Improper Input Validation

CVSS v3.1 Base Score 8.8
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-330: Use of Insufficiently Random Values

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-121: Stack-based Buffer Overflow

CVSS v3.1 Base Score 7.3
CVSS Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-352: Cross-Site Request Forgery (CSRF)

CVSS v3.1 Base Score 2.6
CVSS Vector CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
CWE: CWE-284: Improper Access Control

CVSS v3.1 Base Score 7.9
CVSS Vector CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CVSS v3.1 Base Score 8.2
CVSS Vector CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H/E:P/RL:O/RC:C
CWE: CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’)

CVSS v3.1 Base Score 9.6
CVSS Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’)

CVSS v3.1 Base Score 7.4
CVSS Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-125: Out-of-bounds Read

https://www.siemens.com/cert/advisories