Lucene search

K
cve[email protected]CVE-2013-3633
HistoryMay 24, 2013 - 8:55 p.m.

CVE-2013-3633

2013-05-2420:55:01
CWE-264
web.nvd.nist.gov
26
vulnerability
scalance x-200
scalance x-200irt
switch
web interface
privilege escalation
nvd
cve-2013-3633

8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:P/I:P/A:C

6.8 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

53.6%

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V4.5.0 for CVE-2013-3634), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.1.0). The user privileges for the web interface are only enforced on client side and not properly verified on server side. Therefore, an attacker is able to execute privileged commands using an unprivileged account.

Affected configurations

NVD
Node
siemensscalance_x200irt_firmwareRange5.0.0
AND
siemensscalance_x200-4p_irtMatch-
OR
siemensscalance_x201-3p_irtMatch-
OR
siemensscalance_x201-3p_irtMatch--pro
OR
siemensscalance_x202-2irtMatch-
OR
siemensscalance_x202-2p_irtMatch-
OR
siemensscalance_x202-2p_irtMatch--pro
OR
siemensscalance_x204irtMatch-
OR
siemensscalance_x204irtMatch--pro
OR
siemensscalance_xf204irtMatch-

8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:P/I:P/A:C

6.8 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

53.6%