PT-2013-5881 · Siemens · Scalance X-200Irt+1

Published

2013-10-03

·

Updated

2020-02-10

·

CVE-2013-5944

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Siemens SCALANCE X-200 switches versions prior to 4.5.0 Siemens SCALANCE X-200IRT switches versions prior to 5.1.0
Description The issue concerns the integrated web server on certain Siemens switches, which fails to properly enforce authentication requirements. This allows remote attackers to perform administrative actions by sending requests to the management interface.
Recommendations For Siemens SCALANCE X-200 switches versions prior to 4.5.0, update to version 4.5.0 or later to resolve the issue. For Siemens SCALANCE X-200IRT switches versions prior to 5.1.0, update to version 5.1.0 or later to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5944

Affected Products

Scalance X-200
Scalance X-200Irt