MEDIUM · 6.8

CVE-2015-1049

The web server on Siemens SCALANCE X-200IRT switches with firmware before 5.2.0 allows remote attackers to hijack sessions via unspecified vectors.

Vulnerability Description

The web server on Siemens SCALANCE X-200IRT switches with firmware before 5.2.0 allows remote attackers to hijack sessions via unspecified vectors.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
SiemensScalance X-200 Series Firmware<= 5.1.1
SiemensScalance X201-3P Irt ProAll versions
SiemensScalance X201-3PirtAll versions
SiemensScalance X202-2IrtAll versions
SiemensScalance X202-2P IrtAll versions
SiemensScalance X202-2P Irt ProAll versions
SiemensScalance X202-4P IrtAll versions
SiemensScalance X204IrtAll versions
SiemensScalance X204Irt ProAll versions
SiemensScalance Xf204IrtAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-1049?

CVE-2015-1049 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The web server on Siemens SCALANCE X-200IRT switches with firmware before 5.2.0 allows remote attackers to hijack sessions via unspecified vectors.

How severe is CVE-2015-1049?

CVE-2015-1049 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-1049?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Scalance X-200 Series Firmware, Siemens Scalance X201-3P Irt Pro, Siemens Scalance X201-3Pirt, Siemens Scalance X202-2Irt, Siemens Scalance X202-2P Irt.