CVE-2022-36323
Last modified
CVE-2022-36323 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.. EPSS estimates a 1.32% chance of exploitation in the next 30 days.
Description
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Scalance M-800 Firmware | All versions |
| Siemens | Scalance S615 Firmware | All versions |
| Siemens | Scalance Sc-600 Firmware | < 2.3.1 |
| Siemens | Scalance Sc622-2c Firmware | < 2.3.1 |
| Siemens | Scalance Sc632-2c Firmware | < 2.3.1 |
| Siemens | Scalance Sc636-2c Firmware | < 2.3.1 |
| Siemens | Scalance Sc642-2c Firmware | < 2.3.1 |
| Siemens | Scalance Sc646-2c Firmware | < 2.3.1 |
| Siemens | Scalance W700 Ieee 802.11ax Firmware | All versions |
| Siemens | Scalance W700 Ieee 802.11n Firmware | All versions |
| Siemens | Scalance W700 Ieee 802.11ac Firmware | All versions |
| Siemens | Scalance Xb-200 Firmware | All versions |
| Siemens | Scalance Xb205-3 Firmware | All versions |
| Siemens | Scalance Xb205-3ld Firmware | All versions |
| Siemens | Scalance Xb208 Firmware | All versions |
| Siemens | Scalance Xb213-3 Firmware | All versions |
| Siemens | Scalance Xb213-3ld Firmware | All versions |
| Siemens | Scalance Xb216 Firmware | All versions |
| Siemens | Scalance Xc-200 Firmware | All versions |
| Siemens | Scalance Xc206-2 Firmware | All versions |
| Siemens | Scalance Xc206-2g Poe Firmware | All versions |
| Siemens | Scalance Xc206-2g Poe Eec Firmware | All versions |
| Siemens | Scalance Xc206-2sfp Eec Firmware | All versions |
| Siemens | Scalance Xc206-2sfp G Firmware | All versions |
| Siemens | Scalance Xc206-2sfp G \(E\/Ip\) Firmware | All versions |
| Siemens | Scalance Xc206-2sfp G Eec Firmware | All versions |
| Siemens | Scalance Xc208 Firmware | All versions |
| Siemens | Scalance Xc208eec Firmware | All versions |
| Siemens | Scalance Xc208g Firmware | All versions |
| Siemens | Scalance Xc208g \(E\/Ip\) Firmware | All versions |
| Siemens | Scalance Xc208g Eec Firmware | All versions |
| Siemens | Scalance Xc208g Poe Firmware | All versions |
| Siemens | Scalance Xc216 Firmware | All versions |
| Siemens | Scalance Xc216-4c Firmware | All versions |
| Siemens | Scalance Xc216-4c G Firmware | All versions |
| Siemens | Scalance Xc216-4c G \(E\/Ip\) Firmware | All versions |
| Siemens | Scalance Xc216-4c G Eec Firmware | All versions |
| Siemens | Scalance Xc216eec Firmware | All versions |
| Siemens | Scalance Xc224 Firmware | All versions |
| Siemens | Scalance Xc224-4c G Firmware | All versions |
| Siemens | Scalance Xc224-4c G \(E\/Ip\) Firmware | All versions |
| Siemens | Scalance Xc224-4c G Eec Firmware | All versions |
| Siemens | Scalance Xf-200ba Firmware | All versions |
| Siemens | Scalance Xf204-2ba Dna Firmware | All versions |
| Siemens | Scalance Xf204-2ba Irt Firmware | All versions |
| Siemens | Scalance Xm400 Firmware | All versions |
| Siemens | Scalance Xm408-4c Firmware | All versions |
| Siemens | Scalance Xm408-4c L3 Firmware | All versions |
| Siemens | Scalance Xm408-8c Firmware | All versions |
| Siemens | Scalance Xm408-8c L3 Firmware | All versions |
Showing 50 of 90 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-36323?
How severe is CVE-2022-36323?
How do I fix CVE-2022-36323?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-36318When visiting directory listings for `chrome://` URLs as sou…5.3
- CVE-2022-36319When combining CSS properties for overflow and transform, th…7.5
- CVE-2022-3632The OAuth Client by DigitialPixies WordPress plugin through …6.5
- CVE-2022-36320Mozilla developers and the Mozilla Fuzzing Team reported mem…9.8
- CVE-2022-36321In JetBrains TeamCity before 2022.04.2 the private SSH key c…6.5
- CVE-2022-36322In JetBrains TeamCity before 2022.04.2 build parameter injec…8.8
- CVE-2022-36324Affected devices do not properly handle the renegotiation of…7.5
- CVE-2022-36325Affected devices do not properly sanitize data introduced by…4.8
- CVE-2022-36326An uncontrolled resource consumption vulnerability issue tha…4.9
- CVE-2022-36327Improper Limitation of a Pathname to a Restricted Directory …9.8
- CVE-2022-36328Improper Limitation of a Pathname to a Restricted Directory …4.9
- CVE-2022-36329An improper privilege management issue that could allow an a…7.5
Are you affected by CVE-2022-36323?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
