CVE-2023-29054 Details
Description
A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT PRO (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2P IRT (All versions < V5.5.2), SCALANCE X202-2P IRT PRO (All versions < V5.5.2), SCALANCE X204IRT (All versions < V5.5.2), SCALANCE X204IRT (All versions < V5.5.2), SCALANCE X204IRT PRO (All versions < V5.5.2), SCALANCE XF201-3P IRT (All versions < V5.5.2), SCALANCE XF202-2P IRT (All versions < V5.5.2), SCALANCE XF204-2BA IRT (All versions < V5.5.2), SCALANCE XF204IRT (All versions < V5.5.2), SIPLUS NET SCALANCE X202-2P IRT (All versions < V5.5.2). The SSH server on affected devices is configured to offer weak ciphers by default. This could allow an unauthorized attacker in a man-in-the-middle position to read and modify any data passed over the connection between legitimate clients and the affected device.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-479249.pdf | CVE | Vendor Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-479249.pdf | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-326 | Inadequate Encryption Strength | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| siemens scalance x200-4p irt firmware | < 5.5.2 |
CPE
Remediation
| |
| siemens scalance x200-4p irt | All versions |
CPE
Remediation
| |
| siemens scalance x201-3p irt firmware | < 5.5.2 |
CPE
Remediation
| |
| siemens scalance x201-3p irt | All versions |
CPE
Remediation
| |
| siemens scalance x201-3p irt pro firmware | < 5.5.2 |
CPE
Remediation
| |
| siemens scalance x201-3p irt pro | All versions |
CPE
Remediation
| |
| siemens scalance x202-2irt firmware | < 5.5.2 |
CPE
Remediation
| |
| siemens scalance x202-2irt | All versions |
CPE
Remediation
| |
| siemens scalance x202-2p irt firmware | < 5.5.2 |
CPE
Remediation
| |
| siemens scalance x202-2p irt | All versions |
CPE
Remediation
| |
| siemens scalance x202-2p irt pro firmware | < 5.5.2 |
CPE
Remediation
| |
| siemens scalance x202-2p irt pro | All versions |
CPE
Remediation
| |
| siemens scalance x204irt firmware | < 5.5.2 |
CPE
Remediation
| |
| siemens scalance x204irt | All versions |
CPE
Remediation
| |
| siemens scalance x204irt pro firmware | < 5.5.2 |
CPE
Remediation
| |
| siemens scalance x204irt pro | All versions |
CPE
Remediation
| |
| siemens scalance xf201-3p irt firmware | < 5.5.2 |
CPE
Remediation
| |
| siemens scalance xf201-3p irt | All versions |
CPE
Remediation
| |
| siemens scalance xf202-2p irt firmware | < 5.5.2 |
CPE
Remediation
| |
| siemens scalance xf202-2p irt | All versions |
CPE
Remediation
| |
| siemens scalance xf204-2ba irt firmware | < 5.5.2 |
CPE
Remediation
| |
| siemens scalance xf204-2ba irt | All versions |
CPE
Remediation
| |
| siemens scalance xf204irt firmware | < 5.5.2 |
CPE
Remediation
| |
| siemens scalance xf204irt | All versions |
CPE
Remediation
| |
| siemens siplus net scalance x202-2p irt firmware | < 5.5.2 |
CPE
Remediation
| |
| siemens siplus net scalance x202-2p irt | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 20, 2023 | Initial Analysis | [email protected] |