The vendor explicitly identifies these products as affected by this CVE.
- SCALANCE X200-4P IRT (6GK5200-4AH00-2BA3)
- SCALANCE X201-3P IRT (6GK5201-3BH00-2BA3)
- SCALANCE X201-3P IRT PRO (6GK5201-3JR00-2BA6)
- SCALANCE X202-2IRT (6GK5202-2BB00-2BA3)
- SCALANCE X202-2P IRT (6GK5202-2BH00-2BA3)
- SCALANCE X202-2P IRT PRO (6GK5202-2JR00-2BA6)
- SCALANCE X204-2 (6GK5204-2BB10-2AA3)
- SCALANCE X204-2FM (6GK5204-2BB11-2AA3)
- SCALANCE X204-2LD (6GK5204-2BC10-2AA3)
- SCALANCE X204-2LD TS (6GK5204-2BC10-2CA2)
- SCALANCE X204-2TS (6GK5204-2BB10-2CA2)
- SCALANCE X204IRT (6GK5204-0BA00-2BA3)
- Summary
- authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege-separated child process.
- Remediation
- Update to V5.5.2 or later version
