CVE-2023-44317
Last modified
CVE-2023-44317 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.2.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V7.2.2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V7.2.2), SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2) (All versions < V7.2.2), SCALANCE M816-1 ADSL-Router (6GK5816-1AA00-2AA2) (All versions < V7.2.2), SCALANCE M816-1 ADSL-Router (6GK5816-1BA00-2AA2) (All versions < V7.2.2), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V7.2.2), SCALANCE M874-2 (6GK5874-2AA00-2AA2) (All versions < V7.2.2), SCALANCE M874-3 (6GK5874-3AA00-2AA2) (All versions < V7.2.2), SCALANCE M876-3 (6GK5876-3AA02-2BA2) (All versions < V7.2.2), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (All versions < V7.2.2), SCALANCE M876-4 (6GK5876-4AA10-2BA2) (All versions < V7.2.2), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (All versions < V7.2.2), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (All versions < V7.2.2), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (All versions < V7.2.2), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (All versions < V7.2.2), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (All versions < V7.2.2), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2) (All versions < V7.2.2), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2) (All versions < V7.2.2), SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) (All versions < V3.0.0), SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0) (All versions < V3.0.0), SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0) (All versions < V3.0.0), SCALANCE WAM766-1 (6GK5766-1GE00-7DA0) (All versions < V3.0.0), SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0) (All versions < V3.0.0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0) (All versions < V3.0.0), SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0) (All versions < V3.0.0), SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0) (All versions < V3.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0) (All versions < V3.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0) (All versions < V3.0.0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0) (All versions < V3.0.0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0) (All versions < V3.0.0), SCALANCE WUM766-1 (6GK5766-1GE00-3DA0) (All versions < V3.0.0), SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0) (All versions < V3.0.0), SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0) (All versions < V3.0.0). Affected products do not properly validate the content of uploaded X509 certificates which could allow an attacker with administrative privileges to execute arbitrary code on the device.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.2.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V7.2.2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V7.2.2), SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2) (All versions < V7.2.2), SCALANCE M816-1 ADSL-Router (6GK5816-1AA00-2AA2) (All versions < V7.2.2), SCALANCE M816-1 ADSL-Router (6GK5816-1BA00-2AA2) (All versions < V7.2.2), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V7.2.2), SCALANCE M874-2 (6GK5874-2AA00-2AA2) (All versions < V7.2.2), SCALANCE M874-3 (6GK5874-3AA00-2AA2) (All versions < V7.2.2), SCALANCE M876-3 (6GK5876-3AA02-2BA2) (All versions < V7.2.2), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (All versions < V7.2.2), SCALANCE M876-4 (6GK5876-4AA10-2BA2) (All versions < V7.2.2), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (All versions < V7.2.2), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (All versions < V7.2.2), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (All versions < V7.2.2), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (All versions < V7.2.2), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (All versions < V7.2.2), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2) (All versions < V7.2.2), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2) (All versions < V7.2.2), SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) (All versions < V3.0.0), SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0) (All versions < V3.0.0), SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0) (All versions < V3.0.0), SCALANCE WAM766-1 (6GK5766-1GE00-7DA0) (All versions < V3.0.0), SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0) (All versions < V3.0.0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0) (All versions < V3.0.0), SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0) (All versions < V3.0.0), SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0) (All versions < V3.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0) (All versions < V3.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0) (All versions < V3.0.0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0) (All versions < V3.0.0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0) (All versions < V3.0.0), SCALANCE WUM766-1 (6GK5766-1GE00-3DA0) (All versions < V3.0.0), SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0) (All versions < V3.0.0), SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0) (All versions < V3.0.0). Affected products do not properly validate the content of uploaded X509 certificates which could allow an attacker with administrative privileges to execute arbitrary code on the device.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Scalance Xb208 \(E\/Ip\) Firmware | All versions |
| Siemens | Scalance Xb208 \(Pn\) Firmware | All versions |
| Siemens | Scalance Xb216 \(E\/Ip\) Firmware | All versions |
| Siemens | Scalance Xb216 \(Pn\) Firmware | All versions |
| Siemens | Scalance Xc206-2 \(Sc\) Firmware | All versions |
| Siemens | Scalance Xc206-2 \(St\/Bfoc\) Firmware | All versions |
| Siemens | Scalance Xc206-2g Poe Firmware | All versions |
| Siemens | Scalance Xc206-2g Poe \(54 V Dc\) Firmware | All versions |
| Siemens | Scalance Xc206-2g Poe Eec \(54 V Dc\) Firmware | All versions |
| Siemens | Scalance Xc206-2sfp Firmware | All versions |
| Siemens | Scalance Xc206-2sfp Eec Firmware | All versions |
| Siemens | Scalance Xc206-2sfp G Firmware | All versions |
| Siemens | Scalance Xc206-2sfp G \(Eip Def.\) Firmware | All versions |
| Siemens | Scalance Xc206-2sfp G Eec Firmware | All versions |
| Siemens | Scalance Xc208 Firmware | All versions |
| Siemens | Scalance Xc208eec Firmware | All versions |
| Siemens | Scalance Xc208g Firmware | All versions |
| Siemens | Scalance Xc208g \(Eip Def.\) Firmware | All versions |
| Siemens | Scalance Xc208g Eec Firmware | All versions |
| Siemens | Scalance Xc208g Poe Firmware | All versions |
| Siemens | Scalance Xc208g Poe \(54 V Dc\) Firmware | All versions |
| Siemens | Scalance Xc216 Firmware | All versions |
| Siemens | Scalance Xc216-3g Poe Firmware | All versions |
| Siemens | Scalance Xc216-3g Poe \(54 V Dc\) Firmware | All versions |
| Siemens | Scalance Xc216-4c Firmware | All versions |
| Siemens | Scalance Xc216-4c G Firmware | All versions |
| Siemens | Scalance Xc216-4c G \(Eip Def.\) Firmware | All versions |
| Siemens | Scalance Xc216-4c G Eec Firmware | All versions |
| Siemens | Scalance Xc216eec Firmware | All versions |
| Siemens | Scalance Xc224 Firmware | All versions |
| Siemens | Scalance Xc224-4c G Firmware | All versions |
| Siemens | Scalance Xc224-4c G \(Eip Def.\) Firmware | All versions |
| Siemens | Scalance Xc224-4c G Eec Firmware | All versions |
| Siemens | Scalance Xf204 Firmware | All versions |
| Siemens | Scalance Xf204 Dna Firmware | All versions |
| Siemens | Scalance Xf204-2ba Firmware | All versions |
| Siemens | Scalance Xf204-2ba Dna Firmware | All versions |
| Siemens | Scalance Xp208 Firmware | All versions |
| Siemens | Scalance Xp208 \(Ethernet\/Ip\) Firmware | All versions |
| Siemens | Scalance Xp208eec Firmware | All versions |
| Siemens | Scalance Xp208poe Eec Firmware | All versions |
| Siemens | Scalance Xp216 Firmware | All versions |
| Siemens | Scalance Xp216 \(Ethernet\/Ip\) Firmware | All versions |
| Siemens | Scalance Xp216eec Firmware | All versions |
| Siemens | Scalance Xp216poe Eec Firmware | All versions |
| Siemens | Scalance Xr326-2c Poe Wg Firmware | All versions |
| Siemens | Scalance Xr326-2c Poe Wg \(Without Ul\) Firmware | All versions |
| Siemens | Siplus Net Scalance Xc206-2 Firmware | All versions |
| Siemens | Siplus Net Scalance Xc206-2sfp Firmware | All versions |
| Siemens | Siplus Net Scalance Xc208 Firmware | All versions |
Showing 50 of 69 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-44317?
How severe is CVE-2023-44317?
How do I fix CVE-2023-44317?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-4431Out of bounds memory access in Fonts in Google Chrome prior …8.1
- CVE-2023-44310Stored cross-site scripting (XSS) vulnerability in Page Tree…5.4
- CVE-2023-44311Multiple reflected cross-site scripting (XSS) vulnerabilitie…6.1
- CVE-2023-44312Exposure of Sensitive Information to an Unauthorized Actor i…7.5
- CVE-2023-44313Server-Side Request Forgery (SSRF) vulnerability in Apache S…7.5
- CVE-2023-44315A vulnerability has been identified in SINEC NMS (All versio…5.4
- CVE-2023-44318Affected devices use a hardcoded key to obfuscate the config…4.9
- CVE-2023-44319A vulnerability has been identified in RUGGEDCOM RM1224 LTE(…4.9
- CVE-2023-4432Cross-site Scripting (XSS) - Reflected in GitHub repository …6.1
- CVE-2023-44320A vulnerability has been identified in RUGGEDCOM RM1224 LTE(…4.3
- CVE-2023-44321Affected devices do not properly validate the length of inpu…6.5
- CVE-2023-44322A vulnerability has been identified in RUGGEDCOM RM1224 LTE(…5.9
Are you affected by CVE-2023-44317?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
