CVE-2020-28395: Siemens Scalance XR324-12m Firmware
Medium severity, CVSS 5.9. EPSS: 1.2% chance of exploitation in the next 30 days.
A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do not create a new unique private key after factory reset. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic.
Affected products
- Siemens Scalance XR324-12m Firmware: before 4.1.0 (fixed in 4.1.0)
- Siemens Scalance XR324-12m Ts Firmware: before 4.1.0 (fixed in 4.1.0)
- Siemens Scalance XR324-4m Eec Firmware: before 4.1.0 (fixed in 4.1.0)
- Siemens Scalance XR324-4m Poe Firmware: before 4.1.0 (fixed in 4.1.0)
- Siemens Scalance XR324-4m Poe Ts Firmware: before 4.1.0 (fixed in 4.1.0)
- Siemens Scalance XR324WG Firmware: before 4.1.0 (fixed in 4.1.0)
- Siemens Scalance XR326-2c Poe Wg Firmware: before 4.1.0 (fixed in 4.1.0)
- Siemens Scalance XR328-4c Wg Firmware: before 4.1.0 (fixed in 4.1.0)
Published 2021-01-12. Last modified 2026-06-17.