Vulnerability Description
Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers to bypass intended access restrictions via TCP traffic to port (1) 21 or (2) 23.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Sinamics S\/G Family Firmware | <= 4.6 |
| Siemens | Sinamics G110 | - |
| Siemens | Sinamics G110D | - |
| Siemens | Sinamics G120 | - |
| Siemens | Sinamics G120C | - |
| Siemens | Sinamics G120D | - |
| Siemens | Sinamics G120P | - |
| Siemens | Sinamics G130 | - |
| Siemens | Sinamics G150 | - |
| Siemens | Sinamics G180 | - |
| Siemens | Sinamics S110 | - |
| Siemens | Sinamics S120 | - |
| Siemens | Sinamics S120Cm | - |
| Siemens | Sinamics S150 | - |
Related Weaknesses (CWE)
References
- http://ics-cert.us-cert.gov/advisories/ICSA-13-338-01US Government Resource
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_adviVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-742938.pdf
- http://ics-cert.us-cert.gov/advisories/ICSA-13-338-01US Government Resource
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_adviVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-742938.pdf
FAQ
What is CVE-2013-6920?
CVE-2013-6920 is a vulnerability with a CVSS score of 10.0 (HIGH). Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers to bypass intended access restrictions via TCP tra...
How severe is CVE-2013-6920?
CVE-2013-6920 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-6920?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Sinamics S\/G Family Firmware, Siemens Sinamics G110, Siemens Sinamics G110D, Siemens Sinamics G120, Siemens Sinamics G120C.