


Perceptive Security
SOC/SIEM Consultancy

Siemens SCALANCE
Published:
21 April 2026 at 12:00:00
Alert date:
21 April 2026 at 18:10:28
Source:
cisa.gov
Critical Infrastructure, Network Infrastructure, Mobile & IoT
CISA advisory ICSA-26-111-07 addresses multiple critical vulnerabilities affecting Siemens SCALANCE W-700 IEEE 802.11n family devices before version 6.6.0. The vulnerabilities include Wi-Fi injection attacks, authentication bypasses, OpenSSL flaws, privilege escalation, command injection, DoS conditions, and XSS vulnerabilities. The highest CVSS score is 9.1 (Critical). All affected devices require immediate update to version 6.6.0 or later. Vulnerabilities span from 2020 to 2023 and affect critical infrastructure sectors including Communications, Information Technology, and Critical Manufacturing.
Technical details
Mitigation steps:
Affected products:
Siemens SCALANCE W-700 IEEE 802.11n family
Related links:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-07
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-111-07.json
https://support.industry.siemens.com/cs/ww/en/view/109996102/
https://www.cve.org/CVERecord?id=CVE-2020-24588
https://www.cve.org/CVERecord?id=CVE-2020-26139
https://www.cve.org/CVERecord?id=CVE-2020-26140
https://www.cve.org/CVERecord?id=CVE-2020-26141
https://www.cve.org/CVERecord?id=CVE-2020-26143
https://www.cve.org/CVERecord?id=CVE-2020-26144
https://www.cve.org/CVERecord?id=CVE-2020-26146
https://www.cve.org/CVERecord?id=CVE-2020-26147
https://www.cve.org/CVERecord?id=CVE-2021-3712
https://www.cve.org/CVERecord?id=CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-31765
https://www.cve.org/CVERecord?id=CVE-2022-36323
https://www.cve.org/CVERecord?id=CVE-2022-36324
https://www.cve.org/CVERecord?id=CVE-2022-36325
https://www.cve.org/CVERecord?id=CVE-2023-44373
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
