CVE-2013-5709

The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware before 5.0.0 does not use a sufficient source of entropy for generating values of random numbers, which makes it easier for remote attackers to hijack sessions by predicting a value.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
siemensscalance_x-200_series_firmware
𝑥
≤ 4.4
siemensscalance_x-200_series_firmware
4.3
siemensscalance_x-200
-
siemensscalance_x-200rna
-
siemensscalance_x200-4p_irt
-
siemensscalance_x201-3p_irt
-
siemensscalance_x201-3p_irt
-
siemensscalance_x202-2irt
-
siemensscalance_x202-2p_irt
-
siemensscalance_x202-2p_irt
-
siemensscalance_x204irt
-
siemensscalance_x204irt
-
siemensscalance_xf-200
-
𝑥
= Vulnerable software versions
Common Weakness Enumeration