ID

VAR-201310-0390


CVE

CVE-2013-5944


TITLE

Siemens SCALANCE X-200 and X-200IRT Vulnerability to execute administrator actions in switch firmware

Trust: 0.8

sources: JVNDB: JVNDB-2013-004482

DESCRIPTION

The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which allows remote attackers to perform administrative actions via requests to the management interface. The Siemens Scalance X200 is an industrial Ethernet switch from Siemens. SCALANCE X-200 and X-200IRT series switches are prone to an authentication-bypass vulnerability. Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and gain administrative access to the affected device. The following products are affected. SCALANCE X-200 running firmware versions prior to 4.5.0 SCALANCE X-200IRT running firmware versions prior to 5.1.0

Trust: 2.79

sources: NVD: CVE-2013-5944 // JVNDB: JVNDB-2013-004482 // CNVD: CNVD-2013-13553 // BID: 62762 // IVD: 9e35be88-2352-11e6-abef-000c29c66e3d // VULHUB: VHN-65946 // VULMON: CVE-2013-5944

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 9e35be88-2352-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-13553

AFFECTED PRODUCTS

vendor:siemensmodel:scalance x-200 seriesscope:eqversion:4.3

Trust: 1.6

vendor:siemensmodel:scalance x-200 seriesscope:lteversion:4.4

Trust: 1.0

vendor:siemensmodel:scalance x-200irtscope:eqversion: -

Trust: 1.0

vendor:siemensmodel:scalance x-200scope:eqversion: -

Trust: 1.0

vendor:siemensmodel:scalance x-200 seriesscope:lteversion:5.0.1

Trust: 1.0

vendor:siemensmodel:scalance x-200scope: - version: -

Trust: 0.8

vendor:siemensmodel:scalance x-200 seriesscope:ltversion:4.5.0 (scalance x-200)

Trust: 0.8

vendor:siemensmodel:scalance x-200 seriesscope:ltversion:5.1.0 (scalance x-200irt)

Trust: 0.8

vendor:siemensmodel:scalance x-200irtscope: - version: -

Trust: 0.8

vendor:siemensmodel:scalancescope:eqversion:x-2004.4.9

Trust: 0.6

vendor:siemensmodel:scalance x-200irtscope:eqversion:5.0.9

Trust: 0.6

vendor:siemensmodel:scalance x-200 seriesscope:eqversion:5.0.1

Trust: 0.6

vendor:siemensmodel:scalance x-200 seriesscope:eqversion:4.4

Trust: 0.6

vendor:siemensmodel:scalance x-200irtscope:eqversion:0

Trust: 0.3

vendor:siemensmodel:scalancescope:eqversion:x-2000

Trust: 0.3

vendor:siemensmodel:scalance x-200irtscope:neversion:5.1.2

Trust: 0.3

vendor:siemensmodel:scalance x-200irtscope:neversion:5.1

Trust: 0.3

vendor:siemensmodel:scalancescope:neversion:x-2004.5

Trust: 0.3

vendor:scalance x 200 seriesmodel: - scope:eqversion:5.0.1

Trust: 0.2

vendor:scalance x 200model: - scope:eqversion: -

Trust: 0.2

vendor:scalance x 200 seriesmodel: - scope:eqversion:4.4

Trust: 0.2

vendor:scalance x 200irtmodel: - scope:eqversion: -

Trust: 0.2

vendor:scalance x 200 seriesmodel: - scope:eqversion:4.3

Trust: 0.2

sources: IVD: 9e35be88-2352-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-13553 // BID: 62762 // JVNDB: JVNDB-2013-004482 // CNNVD: CNNVD-201310-059 // NVD: CVE-2013-5944

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-5944
value: HIGH

Trust: 1.0

NVD: CVE-2013-5944
value: HIGH

Trust: 0.8

CNVD: CNVD-2013-13553
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201310-059
value: CRITICAL

Trust: 0.6

IVD: 9e35be88-2352-11e6-abef-000c29c66e3d
value: CRITICAL

Trust: 0.2

VULHUB: VHN-65946
value: HIGH

Trust: 0.1

VULMON: CVE-2013-5944
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2013-5944
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2013-13553
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 9e35be88-2352-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-65946
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: IVD: 9e35be88-2352-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-13553 // VULHUB: VHN-65946 // VULMON: CVE-2013-5944 // JVNDB: JVNDB-2013-004482 // CNNVD: CNNVD-201310-059 // NVD: CVE-2013-5944

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.9

sources: VULHUB: VHN-65946 // JVNDB: JVNDB-2013-004482 // NVD: CVE-2013-5944

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201310-059

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201310-059

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-004482

PATCH

title:SSA-176087url:http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-176087.pdf

Trust: 0.8

title:Patch for unclear management access vulnerability on the WEB interface of the Siemens SCALANCE X-200 switchurl:https://www.cnvd.org.cn/patchInfo/show/40012

Trust: 0.6

title:Siemens Scalance X-200 Switch unauthorized access vulnerability fixurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=109052

Trust: 0.6

title:Siemens Security Advisories: Siemens Security Advisoryurl:https://vulmon.com/vendoradvisory?qidtp=siemens_security_advisories&qid=44f98d989f2a58ed7cb2e4b6335cb180

Trust: 0.1

sources: CNVD: CNVD-2013-13553 // VULMON: CVE-2013-5944 // JVNDB: JVNDB-2013-004482 // CNNVD: CNNVD-201310-059

EXTERNAL IDS

db:NVDid:CVE-2013-5944

Trust: 3.7

db:SIEMENSid:SSA-176087

Trust: 2.7

db:BIDid:62762

Trust: 1.0

db:CNNVDid:CNNVD-201310-059

Trust: 0.9

db:CNVDid:CNVD-2013-13553

Trust: 0.8

db:JVNDBid:JVNDB-2013-004482

Trust: 0.8

db:IVDid:9E35BE88-2352-11E6-ABEF-000C29C66E3D

Trust: 0.2

db:SEEBUGid:SSVID-89659

Trust: 0.1

db:VULHUBid:VHN-65946

Trust: 0.1

db:ICS CERTid:ICSA-13-274-01

Trust: 0.1

db:VULMONid:CVE-2013-5944

Trust: 0.1

sources: IVD: 9e35be88-2352-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-13553 // VULHUB: VHN-65946 // VULMON: CVE-2013-5944 // BID: 62762 // JVNDB: JVNDB-2013-004482 // CNNVD: CNNVD-201310-059 // NVD: CVE-2013-5944

REFERENCES

url:http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-176087.pdf

Trust: 2.7

url:https://cert-portal.siemens.com/productcert/pdf/ssa-176087.pdf

Trust: 1.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-5944

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-5944

Trust: 0.8

url:http://subscriber.communications.siemens.com/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/287.html

Trust: 0.1

url:http://tools.cisco.com/security/center/viewalert.x?alertid=31114

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://ics-cert.us-cert.gov/advisories/icsa-13-274-01

Trust: 0.1

sources: CNVD: CNVD-2013-13553 // VULHUB: VHN-65946 // VULMON: CVE-2013-5944 // BID: 62762 // JVNDB: JVNDB-2013-004482 // CNNVD: CNNVD-201310-059 // NVD: CVE-2013-5944

CREDITS

Eireann Leverett of IOActive

Trust: 0.3

sources: BID: 62762

SOURCES

db:IVDid:9e35be88-2352-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2013-13553
db:VULHUBid:VHN-65946
db:VULMONid:CVE-2013-5944
db:BIDid:62762
db:JVNDBid:JVNDB-2013-004482
db:CNNVDid:CNNVD-201310-059
db:NVDid:CVE-2013-5944

LAST UPDATE DATE

2024-11-23T21:55:30.640000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-13553date:2013-10-10T00:00:00
db:VULHUBid:VHN-65946date:2020-02-10T00:00:00
db:VULMONid:CVE-2013-5944date:2020-02-10T00:00:00
db:BIDid:62762date:2013-10-01T00:00:00
db:JVNDBid:JVNDB-2013-004482date:2013-10-07T00:00:00
db:CNNVDid:CNNVD-201310-059date:2020-02-11T00:00:00
db:NVDid:CVE-2013-5944date:2024-11-21T01:58:28.080

SOURCES RELEASE DATE

db:IVDid:9e35be88-2352-11e6-abef-000c29c66e3ddate:2013-10-10T00:00:00
db:CNVDid:CNVD-2013-13553date:2013-10-10T00:00:00
db:VULHUBid:VHN-65946date:2013-10-03T00:00:00
db:VULMONid:CVE-2013-5944date:2013-10-03T00:00:00
db:BIDid:62762date:2013-10-01T00:00:00
db:JVNDBid:JVNDB-2013-004482date:2013-10-07T00:00:00
db:CNNVDid:CNNVD-201310-059date:2013-10-09T00:00:00
db:NVDid:CVE-2013-5944date:2013-10-03T11:04:43.773