Vulnerabilities
Vulnerable Software
Siemens:  >> Scalance Xr-300poe  Security Vulnerabilities
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.
CVSS Score
9.1
EPSS Score
0.004
Published
2022-08-10
Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of service condition for the duration of the attack.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-08-10
Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS.
CVSS Score
6.8
EPSS Score
0.001
Published
2022-08-10
The FTP server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote authenticated users to cause a denial of service (reboot) via crafted FTP packets.
CVSS Score
6.8
EPSS Score
0.004
Published
2015-01-21
The web server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote attackers to cause a denial of service (reboot) via malformed HTTP requests.
CVSS Score
7.8
EPSS Score
0.005
Published
2015-01-21


Contact Us

Shodan ® - All rights reserved