Vulnerability Description
The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware before 5.0.0 does not use a sufficient source of entropy for generating values of random numbers, which makes it easier for remote attackers to hijack sessions by predicting a value.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Scalance X-200 Series Firmware | <= 4.4 |
| Siemens | Scalance X-200 | - |
| Siemens | Scalance X-200Rna | - |
| Siemens | Scalance X200-4P Irt | - |
| Siemens | Scalance X201-3P Irt | - |
| Siemens | Scalance X202-2Irt | - |
| Siemens | Scalance X202-2P Irt | - |
| Siemens | Scalance X204Irt | - |
| Siemens | Scalance Xf-200 | - |
Related Weaknesses (CWE)
References
- http://ics-cert.us-cert.gov/advisories/ICSA-13-254-01US Government Resource
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_secVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-850708.pdf
- http://ics-cert.us-cert.gov/advisories/ICSA-13-254-01US Government Resource
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_secVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-850708.pdf
FAQ
What is CVE-2013-5709?
CVE-2013-5709 is a vulnerability with a CVSS score of 8.3 (HIGH). The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware before 5.0.0 does not use a sufficient source of entropy for generating values of random numbers, w...
How severe is CVE-2013-5709?
CVE-2013-5709 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-5709?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Scalance X-200 Series Firmware, Siemens Scalance X-200, Siemens Scalance X-200Rna, Siemens Scalance X200-4P Irt, Siemens Scalance X201-3P Irt.