HIGH · 10.0

CVE-2013-5944

The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which al...

Vulnerability Description

The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which allows remote attackers to perform administrative actions via requests to the management interface.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
SiemensScalance X-200 Series Firmware<= 4.4
SiemensScalance X-200-
SiemensScalance X-200Irt-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-5944?

CVE-2013-5944 is a vulnerability with a CVSS score of 10.0 (HIGH). The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which al...

How severe is CVE-2013-5944?

CVE-2013-5944 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-5944?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Scalance X-200 Series Firmware, Siemens Scalance X-200, Siemens Scalance X-200Irt.