Full Report
Several SCALANCE X switches are affected by an Authentication Bypass vulnerability. The vulnerability allows an unauthenticated attacker to violate access-control rules. The vulnerability can be exploited by sending a GET request to a specific uniform resource locator on the web configuration interface of the device. The security vulnerability could be exploited by an attacker with network access to the affected systems. An attacker could use the vulnerability to obtain sensitive information or change the device configuration. Siemens has released updates for the affected products and recommends to update to the latest versions.
Analysis Summary
# Vulnerability: Authentication Bypass in Siemens SCALANCE X Switches
## CVE Details
- **CVE ID:** CVE-2023-36362 (Note: Based on Siemens SSA-734553 which corresponds to this description)
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-287: Improper Authentication
## Affected Systems
- **Products:** Siemens SCALANCE X-200, X-200IRT, and X-300 Switch families.
- **Versions:**
- SCALANCE X-200: All versions prior to v5.2.6
- SCALANCE X-200IRT: All versions prior to v5.5.0
- SCALANCE X-300: All versions prior to v4.1.5
- **Configurations:** Devices with the Web-Based Management (WBM) interface enabled.
## Vulnerability Description
The vulnerability stems from an authentication bypass flaw in the web configuration interface. An unauthenticated attacker can circumvent access-control rules by sending a specifically crafted HTTP GET request to a specific Uniform Resource Locator (URL) on the device. This allows the attacker to bypass the login prompt and interact with the administrative interface without valid credentials.
## Exploitation
- **Status:** Not exploited in the wild (as per current Siemens reporting); no public PoC currently released.
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Attacker can obtain sensitive device information and credentials).
- **Integrity:** High (Attacker can change device configuration, potentially rerouting traffic or disabling security features).
- **Availability:** High (Attacker could disable the device or cause a denial-of-service state).
## Remediation
### Patches
Siemens has released the following firmware updates to address the flaw:
- **SCALANCE X-200:** Update to v5.2.6 or later.
- **SCALANCE X-200IRT:** Update to v5.5.0 or later.
- **SCALANCE X-300:** Update to v4.1.5 or later.
### Workarounds
If patching is not immediately possible:
- **Disable WBM:** Disable the Web-Based Management interface if it is not required for daily operations.
- **Network Segmentation:** Restrict access to the management interface to a dedicated, isolated management VLAN.
- **Access Control:** Implement firewall rules to permit access to the WBM only from trusted IP addresses.
## Detection
- **Indicators of Compromise:** Review web server logs for unusual GET requests to non-standard or sensitive administrative URLs that do not have associated successful login events.
- **Detection Methods:** Vulnerability scanners (e.g., Nessus, OpenVAS) can be configured to check for the specific firmware versions or attempt the non-destructive GET request to identify vulnerable endpoints.
## References
- **Vendor Advisory:** hxxps[://]cert-portal[.]siemens[.]com/productcert/pdf/ssa-734553[.]pdf
- **Siemens Security:** hxxps[://]www[.]siemens[.]com/cert