CVE-2019-6567 Details
Description
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.3), SCALANCE X-414-3E (All versions). The affected devices store passwords in a recoverable format. An attacker may extract and recover device passwords from the device configuration. Successful exploitation requires access to a device configuration backup and impacts confidentiality of the stored passwords.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-646841.pdf | CVE | PatchVendor Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-646841.pdf | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
| CWE-257 | Storing Passwords in a Recoverable Format | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| siemens scalance x-200 firmware | < 5.2.4 |
CPE
Remediation
| |
| siemens scalance x-200 | All versions |
CPE
Remediation
| |
| siemens scalance x-200irt firmware | All versions |
CPE
Remediation
| |
| siemens scalance x-200irt | All versions |
CPE
Remediation
| |
| siemens scalance x-300 firmware | All versions |
CPE
Remediation
| |
| siemens scalance x-300 | All versions |
CPE
Remediation
| |
| siemens scalance x-414-3e firmware | All versions |
CPE
Remediation
| |
| siemens scalance x-414-3e | All versions |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 9, 2021 | CVE Modified | [email protected] |
| Oct 6, 2020 | Modified Analysis | [email protected] |
| Jan 16, 2020 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Jun 19, 2019 | Initial Analysis | [email protected] |