PT-2013-5743 · Siemens · Scalance X-200

Eireann Leverett

·

Published

2013-09-17

·

Updated

2020-02-10

·

CVE-2013-5709

CVSS v2.0

8.3

High

VectorAV:N/AC:M/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions Siemens SCALANCE X-200 switches versions prior to 5.0.0
Description The issue concerns the authentication implementation in the web server, which does not utilize a sufficient source of entropy for generating random numbers. This makes it easier for remote attackers to hijack sessions by predicting a value.
Recommendations For versions prior to 5.0.0, update to version 5.0.0 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5709

Affected Products

Scalance X-200