Vulnerability Description
Unspecified vulnerability in the command-line management interface on Siemens Scalance W7xx devices with firmware before 4.5.4 allows remote attackers to bypass authentication and execute arbitrary code via a (1) SSH or (2) TELNET connection.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Scalance W700 Series Firmware | <= 4.4.0 |
| Siemens | Scalance W744-1 | - |
| Siemens | Scalance W744-1Pro | - |
| Siemens | Scalance W746-1 | - |
| Siemens | Scalance W746-1Pro | - |
| Siemens | Scalance W747-1 | - |
| Siemens | Scalance W747-1Rr | - |
| Siemens | Scalance W784-1 | - |
| Siemens | Scalance W784-1Rr | - |
| Siemens | Scalance W786-1Pro | - |
| Siemens | Scalance W786-2Pro | - |
| Siemens | Scalance W786-2Rr | - |
| Siemens | Scalance W786-3Pro | - |
| Siemens | Scalance W788-1Pro | - |
| Siemens | Scalance W788-1Rr | - |
| Siemens | Scalance W788-2Pro | - |
| Siemens | Scalance W788-2Rr | - |
References
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_secVendor Advisory
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_secVendor Advisory
FAQ
What is CVE-2013-4652?
CVE-2013-4652 is a vulnerability with a CVSS score of 10.0 (HIGH). Unspecified vulnerability in the command-line management interface on Siemens Scalance W7xx devices with firmware before 4.5.4 allows remote attackers to bypass authentication and execute arbitrary co...
How severe is CVE-2013-4652?
CVE-2013-4652 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-4652?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Scalance W700 Series Firmware, Siemens Scalance W744-1, Siemens Scalance W744-1Pro, Siemens Scalance W746-1, Siemens Scalance W746-1Pro.