Siemens SCALANCE X-200RNA Switch Devices Improper Input Validation (CVE-2016-6515)

high Tenable OT Security Plugin ID 503129

Synopsis

The remote OT asset is affected by a vulnerability.

Description

The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows remote attackers to cause a denial of service (crypt CPU consumption) via a long string.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

https://cert-portal.siemens.com/productcert/pdf/ssa-676336.pdf

https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf

https://support.industry.siemens.com/cs/ww/en/view/109814809/

https://support.industry.siemens.com/cs/ww/en/view/109817790/

https://support.industry.siemens.com/cs/ww/en/view/109801131/

https://support.industry.siemens.com/cs/ww/en/view/109808359/

https://www.cisa.gov/news-events/ics-advisories/icsa-22-349-21

Plugin Details

Severity: High

ID: 503129

Version: 1.1

Type: remote

Family: Tenable.ot

Published: 3/13/2025

Updated: 3/13/2025

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:siemens:scalance_xr324-4m_eec_%28100-240vac%2f60-250vdc%2c_ports_on_rear%29_firmware:4.1.4, cpe:/o:siemens:scalance_x302-7_eec_%282x_230v%29_firmware:4.1.4, cpe:/o:siemens:scalance_xr324-4m_poe_ts_%2824v%2c_ports_on_front%29_firmware:4.1.4, cpe:/o:siemens:scalance_x307-2_eec_%282x_230v%2c_coated%29_firmware:4.1.4, cpe:/o:siemens:scalance_x308-2m_ts_firmware:4.1.4, cpe:/o:siemens:scalance_xf202-2p_irt_firmware:5.5.2, cpe:/o:siemens:scalance_x308-2_firmware:4.1.4, cpe:/o:siemens:scalance_x204-2_firmware:5.2.5, cpe:/o:siemens:scalance_xf201-3p_irt_firmware:5.5.2, cpe:/o:siemens:scalance_x216_firmware:5.2.5, cpe:/o:siemens:scalance_x204-2ld_ts_firmware:5.2.5, cpe:/o:siemens:scalance_x307-3ld_firmware:4.1.4, cpe:/o:siemens:scalance_x302-7_eec_%28230v%29_firmware:4.1.4, cpe:/o:siemens:scalance_xr324-4m_eec_%28100-240vac%2f60-250vdc%2c_ports_on_front%29_firmware:4.1.4, cpe:/o:siemens:siplus_net_scalance_x308-2_firmware:4.1.4, cpe:/o:siemens:scalance_xr324-12m_%28230v%2c_ports_on_rear%29_firmware:4.1.4, cpe:/o:siemens:scalance_x200-4p_irt_firmware:5.5.2, cpe:/o:siemens:scalance_x307-2_eec_%28230v%2c_coated%29_firmware:4.1.4, cpe:/o:siemens:scalance_x307-2_eec_%282x_24v%29_firmware:4.1.4, cpe:/o:siemens:scalance_xf204irt_firmware:5.5.2, cpe:/o:siemens:scalance_xr324-4m_poe_%28230v%2c_ports_on_rear%29_firmware:4.1.4, cpe:/o:siemens:scalance_x308-2m_poe_firmware:4.1.4, cpe:/o:siemens:scalance_xr324-4m_eec_%2824v%2c_ports_on_front%29_firmware:4.1.4, cpe:/o:siemens:scalance_x306-1ld_fe_firmware:4.1.4, cpe:/o:siemens:scalance_x302-7_eec_%28230v%2c_coated%29_firmware:4.1.4, cpe:/o:siemens:scalance_x208pro_firmware:5.2.5, cpe:/o:siemens:scalance_x204-2ld_firmware:5.2.5, cpe:/o:siemens:scalance_xr324-4m_poe_%2824v%2c_ports_on_front%29_firmware:4.1.4, cpe:/o:siemens:scalance_xr324-12m_%28230v%2c_ports_on_front%29_firmware:4.1.4, cpe:/o:siemens:scalance_x308-2m_firmware:4.1.4, cpe:/o:siemens:scalance_x307-2_eec_%282x_230v%29_firmware:4.1.4, cpe:/o:siemens:scalance_x202-2p_irt_firmware:5.5.2, cpe:/o:siemens:scalance_x302-7_eec_%2824v%2c_coated%29_firmware:4.1.4, cpe:/o:siemens:scalance_x204-2fm_firmware:5.2.5, cpe:/o:siemens:scalance_x204rna_eec_%28prp%2fhsr%29_firmware:3.2.7, cpe:/o:siemens:scalance_xr324-12m_%2824v%2c_ports_on_rear%29_firmware:4.1.4, cpe:/o:siemens:scalance_x201-3p_irt_pro_firmware:5.5.2, cpe:/o:siemens:scalance_xr324-4m_eec_%282x_24v%2c_ports_on_rear%29_firmware:4.1.4, cpe:/o:siemens:scalance_xr324-4m_poe_%28230v%2c_ports_on_front%29_firmware:4.1.4, cpe:/o:siemens:scalance_x206-1_firmware:5.2.5, cpe:/o:siemens:scalance_x212-2ld_firmware:5.2.5, cpe:/o:siemens:scalance_x302-7_eec_%282x_24v%2c_coated%29_firmware:4.1.4, cpe:/o:siemens:scalance_x206-1ld_firmware:5.2.5, cpe:/o:siemens:scalance_x202-2p_irt_pro_firmware:5.5.2, cpe:/o:siemens:scalance_x307-2_eec_%2824v%29_firmware:4.1.4, cpe:/o:siemens:scalance_x302-7_eec_%282x_24v%29_firmware:4.1.4, cpe:/o:siemens:scalance_x320-1-2ld_fe_firmware:4.1.4, cpe:/o:siemens:scalance_xr324-4m_eec_%2824v%2c_ports_on_rear%29_firmware:4.1.4, cpe:/o:siemens:scalance_x204rna_%28hsr%29_firmware:3.2.7, cpe:/o:siemens:scalance_x204rna_eec_%28prp%29_firmware:3.2.7, cpe:/o:siemens:scalance_x310fe_firmware:4.1.4, cpe:/o:siemens:scalance_x310_firmware:4.1.4, cpe:/o:siemens:scalance_x320-1_fe_firmware:4.1.4, cpe:/o:siemens:scalance_xr324-4m_poe_%2824v%2c_ports_on_rear%29_firmware:4.1.4, cpe:/o:siemens:scalance_x204irt_pro_firmware:5.5.2, cpe:/o:siemens:scalance_x308-2lh%2b_firmware:4.1.4, cpe:/o:siemens:scalance_xr324-4m_eec_%282x_100-240vac%2f60-250vdc%2c_ports_on_rear%29_firmware:4.1.4, cpe:/o:siemens:scalance_xf208_firmware:5.2.5, cpe:/o:siemens:scalance_xr324-12m_%2824v%2c_ports_on_front%29_firmware:4.1.4, cpe:/o:siemens:scalance_x204rna_%28prp%29_firmware:3.2.7, cpe:/o:siemens:scalance_x202-2irt_firmware:5.5.2, cpe:/o:siemens:scalance_x302-7_eec_%282x_230v%2c_coated%29_firmware:4.1.4, cpe:/o:siemens:scalance_xr324-12m_ts_%2824v%29_firmware:4.1.4, cpe:/o:siemens:scalance_x204-2ts_firmware:5.2.5, cpe:/o:siemens:scalance_x307-2_eec_%2824v%2c_coated%29_firmware:4.1.4, cpe:/o:siemens:scalance_x308-2ld_firmware:4.1.4, cpe:/o:siemens:scalance_x224_firmware:5.2.5, cpe:/o:siemens:scalance_x308-2lh_firmware:4.1.4, cpe:/o:siemens:scalance_x408-2_firmware:4.1.4, cpe:/o:siemens:scalance_xf206-1_firmware:5.2.5, cpe:/o:siemens:scalance_x201-3p_irt_firmware:5.5.2, cpe:/o:siemens:scalance_xr324-4m_eec_%282x_100-240vac%2f60-250vdc%2c_ports_on_front%29_firmware:4.1.4, cpe:/o:siemens:scalance_xr324-4m_eec_%282x_24v%2c_ports_on_front%29_firmware:4.1.4, cpe:/o:siemens:scalance_x307-2_eec_%282x_24v%2c_coated%29_firmware:4.1.4, cpe:/o:siemens:scalance_xf204_firmware:5.2.5, cpe:/o:siemens:scalance_x302-7_eec_%2824v%29_firmware:4.1.4, cpe:/o:siemens:scalance_x307-3_firmware:4.1.4, cpe:/o:siemens:scalance_x204irt_firmware:5.5.2, cpe:/o:siemens:scalance_x304-2fe_firmware:4.1.4, cpe:/o:siemens:scalance_x307-2_eec_%28230v%29_firmware:4.1.4, cpe:/o:siemens:scalance_xf204-2ba_irt_firmware:5.5.2, cpe:/o:siemens:scalance_x204rna_eec_%28hsr%29_firmware:3.2.7

Required KB Items: Tenable.ot/Siemens

Exploit Ease: No known exploits are available

Patch Publication Date: 9/14/2021

Vulnerability Publication Date: 9/14/2021

Reference Information

CVE: CVE-2016-6515

CWE: 20

ICSA: 22-349-21