Siemens SCALANCE and RUGGEDCOM Products (Update A)
The Siemens SCALANCE and RUGGEDCOM products do not properly authorize the password change function in the web interface. This allows low-privileged users to escalate their privileges to administrator level. Siemens has released firmware updates for most products (versions 2.0, 3.0, 4.4, 6.6, or 7.1.2 depending on product family), but a large number of SCALANCE W-series wireless access points will not receive patches. For products without updates, Siemens recommends restricting web interface access using network-level access control lists.
- Access to the device web interface (HTTP port 80 or HTTPS port 443)
- Low-privileged user credentials (read-only or operator-level account)
- Device running affected firmware version
Patching may require device reboot — plan for process interruption
/api/v1/advisories/77a1a501-0fb8-424f-8908-967100939768Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.