Vulnerability Description
The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which allows remote attackers to perform administrative actions via requests to the management interface.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Scalance X-200 Series Firmware | <= 4.4 |
| Siemens | Scalance X-200 | - |
| Siemens | Scalance X-200Irt | - |
Related Weaknesses (CWE)
References
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_adviVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-176087.pdf
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_adviVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-176087.pdf
FAQ
What is CVE-2013-5944?
CVE-2013-5944 is a vulnerability with a CVSS score of 10.0 (HIGH). The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which al...
How severe is CVE-2013-5944?
CVE-2013-5944 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-5944?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Scalance X-200 Series Firmware, Siemens Scalance X-200, Siemens Scalance X-200Irt.