Description
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The affected products are vulnerable to an "Exposure of Sensitive Information to an Unauthorized Actor" vulnerability by leaking sensitive data in the HTTP Referer.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected products
- Siemens / SCALANCE X204RNA EEC (HSR)All versions < V3.2.7 – All versions < V3.2.7
- Siemens / SCALANCE X204RNA EEC (PRP)All versions < V3.2.7 – All versions < V3.2.7
- Siemens / SCALANCE X204RNA EEC (PRP/HSR)All versions < V3.2.7 – All versions < V3.2.7
- Siemens / SCALANCE X204RNA (HSR)All versions < V3.2.7 – All versions < V3.2.7
- Siemens / SCALANCE X204RNA (PRP)All versions < V3.2.7 – All versions < V3.2.7