Description
A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do not create a new unique private key after factory reset. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-20854 | A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do not create a new unique private key after factory reset. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic. |
References
History
No history.
Subscriptions
Siemens
Subscribe
Scalance Xr324-12m
Subscribe
Scalance Xr324-12m Firmware
Subscribe
Scalance Xr324-12m Ts
Subscribe
Scalance Xr324-12m Ts Firmware
Subscribe
Scalance Xr324-4m Eec
Subscribe
Scalance Xr324-4m Eec Firmware
Subscribe
Scalance Xr324-4m Poe
Subscribe
Scalance Xr324-4m Poe Firmware
Subscribe
Scalance Xr324-4m Poe Ts
Subscribe
Scalance Xr324-4m Poe Ts Firmware
Subscribe
Scalance Xr324wg
Subscribe
Scalance Xr324wg Firmware
Subscribe
Scalance Xr326-2c Poe Wg
Subscribe
Scalance Xr326-2c Poe Wg Firmware
Subscribe
Scalance Xr328-4c Wg
Subscribe
Scalance Xr328-4c Wg Firmware
Subscribe
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-08-04T16:33:59.028Z
Reserved: 2020-11-10T00:00:00.000Z
Link: CVE-2020-28395
No data.
Status : Modified
Published: 2021-01-12T21:15:18.197
Modified: 2024-11-21T05:22:42.987
Link: CVE-2020-28395
No data.
OpenCVE Enrichment
No data.
EUVD