ICSA-12-102-04
·
Published 2025-06-06
·
View on CISA ICS-CERT ↗
Siemens Scalance X Buffer Overflow Vulnerability
CVSS 7.8
HIGH
CVEs (1)
Remediations
- Siemens has produced firmware updates that resolve this vulnerability for the listed hardware platforms. Siemens strongly recommends installing the updates as soon as possible. Download the appropriate update from the following links: Firmware Update Location (Scalance X414-3E) Firmware Update Location (Scalance X308-2M, X-300EEC, XR-300, X-300) an overview over the Operational Guidelines for Industrial Security with the cell protection concept (http://www.industry.siemens.com/topics/global/en/industrial-security/Documents/operational_guidelines_industrial_security_en.pdf)
- Information about industrial security by Siemens (http://www.siemens.com/industrialsecurity)
- Recommended security practices by US-CERT For further inquiries on vulnerabilities in Siemens products and solutions, please contact the Siemens Product CERT.
- The Siemens Security Advisory is available at (https://cert-portal.siemens.com/productcert/pdf/ssa-130874.pdf).
Affected Vendors
Siemens
Affected Products (5)
Siemens
·
Scalance X414-3E
vers:all/*
Siemens
·
Scalance X308-2M
vers:all/*
Siemens
·
Scalance X-300EEC
vers:all/*
Siemens
·
Scalance XR-300
vers:all/*
Siemens
·
Scalance X-300
vers:all/*
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more