The web server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote attackers to cause a denial of service (reboot) via malformed HTTP requests.
2015-01-21T17:59:00.060
2025-04-12T10:46:40.837
Deferred
CVSSv2: 7.8 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:C
10.0
6.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | siemens | scalance_x-300_series_firmware | ≤ 3.9.3 | Yes |
| Hardware | siemens | scalance_x-300 | - | No |
| Hardware | siemens | scalance_x-300eec | - | No |
| Hardware | siemens | scalance_x-300poe | - | No |
| Hardware | siemens | scalance_xr-300 | - | No |
| Hardware | siemens | scalance_xr-300eec | - | No |
| Hardware | siemens | scalance_xr-300poe | - | No |
| Application | siemens | scalance_x-408_firmware | ≤ 3.9.3 | Yes |
| Hardware | siemens | scalance_x-408 | * | No |