CVE-2022-46355

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The affected products are vulnerable to an "Exposure of Sensitive Information to an Unauthorized Actor" vulnerability by leaking sensitive data in the HTTP Referer.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
siemensCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 43%
VendorProductVersion
siemens6gk5204-0ba00-2mb2_firmware
𝑥
< 3.2.7
siemens6gk5204-0ba00-2kb2_firmware
𝑥
< 3.2.7
siemens6gk5204-0bs00-2na3_firmware
𝑥
< 3.2.7
siemens6gk5204-0bs00-3la3_firmware
𝑥
< 3.2.7
siemens6gk5204-0bs00-3pa3_firmware
𝑥
< 3.2.7
𝑥
= Vulnerable software versions