The vendor explicitly identifies these products as affected by this CVE.
- SCALANCE X204RNA (HSR) (6GK5204-0BA00-2MB2)
- SCALANCE X204RNA (PRP) (6GK5204-0BA00-2KB2)
- SCALANCE X204RNA EEC (HSR) (6GK5204-0BS00-2NA3)
- SCALANCE X204RNA EEC (PRP) (6GK5204-0BS00-3LA3)
- SCALANCE X204RNA EEC (PRP/HSR) (6GK5204-0BS00-3PA3)
- Summary
- The webserver of affected devices calculates session ids and nonces in an insecure manner. This could allow an unauthenticated remote attacker to brute-force session ids and hijack existing sessions.
- Remediation
- Update to V3.2.7 or later version
