Vulnerability record · CVE-2022-36324 · published 10 August 2022
CVE-2022-36324: Siemens scalance m-800 firmware allocation without limits vulnerability
Siemens · Scalance M 800 Firmware
Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of service condition for the duration of the attack.
Description
Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of service condition for the duration of the attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
84 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-019200.html | |
| https://cert-portal.siemens.com/productcert/html/ssa-710008.html | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-710008.pdf | MitigationVendor Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-710008.pdf | MitigationVendor Advisory |
Track CVE-2022-36324 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-36324), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.