CVE-2013-5944

EUVD-2013-5776
The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which allows remote attackers to perform administrative actions via requests to the management interface.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
Affected Products (NVD)
VendorProductVersion
siemensscalance_x-200_series_firmware
𝑥
≤ 4.4
siemensscalance_x-200_series_firmware
4.3
siemensscalance_x-200
-
siemensscalance_x-200_series_firmware
𝑥
≤ 5.0.1
siemensscalance_x-200irt
-
𝑥
= Vulnerable software versions