← Vulnerability feed

Vulnerability record · CVE-2012-1802 · published 18 April 2012

CVE-2012-1802: Siemens scalance x414-3e firmware memory buffer overflow vulnerability

Siemens · Scalance X414 3e Firmware

Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before 3.7.2, XR-300 before 3.7.2, and X-300 before 3.7.2 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a malformed URL.

7.8 CVSS 2.0 High EPSS 6.1% · top 6.9% CWE-119 · Memory buffer overflow
7.8CVSS 2.0 base score
6.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before 3.7.2, XR-300 before 3.7.2, and X-300 before 3.7.2 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a malformed URL.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1802 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2019-6569Siemens scalance x-200 firmware vulnerabilityThe monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network. An attac…EPSS 1.3%8.6CVE-2019-13933Siemens scalance x-200rna firmware missing authentication for critical function vulnerabilityA vulnerability has been identified in SCALANCE X204RNA (HSR), SCALANCE X204RNA (PRP), SCALANCE X204RNA EEC (HSR), SCALANCE X204RNA EEC (PRP), SCALAN…EPSS 1.4%7.5CVE-2019-19301Siemens scalance xc-200 firmware uncontrolled resource consumption vulnerabilityA vulnerability has been identified in SCALANCE X200-4P IRT, SCALANCE X201-3P IRT, SCALANCE X201-3P IRT PRO, SCALANCE X202-2IRT, SCALANCE X202-2P IRT…EPSS 1.4%7.5CVE-2019-13946Siemens dk standard ethernet controller uncontrolled resource consumption vulnerabilityProfinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package request…EPSS 1.5%5.5CVE-2019-6567Siemens scalance x-200 firmware insufficiently protected credentials vulnerabilityA vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch fam…EPSS 0.30%5.4CVE-2019-13924Siemens scalance xc-200 firmware clickjacking vulnerabilityA vulnerability has been identified in SCALANCE S602 (All versions < V4.1), SCALANCE S612 (All versions < V4.1), SCALANCE S623 (All versions < V4.1),…EPSS 0.83%8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1802), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.