CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
77.0%
The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which allows remote attackers to perform administrative actions via requests to the management interface.
Vendor | Product | Version | CPE |
---|---|---|---|
siemens | scalance_x-200_series_firmware | * | cpe:2.3:o:siemens:scalance_x-200_series_firmware:*:*:*:*:*:*:*:* |
siemens | scalance_x-200_series_firmware | 4.3 | cpe:2.3:o:siemens:scalance_x-200_series_firmware:4.3:*:*:*:*:*:*:* |
siemens | scalance_x-200 | - | cpe:2.3:h:siemens:scalance_x-200:-:*:*:*:*:*:*:* |
siemens | scalance_x-200irt | - | cpe:2.3:h:siemens:scalance_x-200irt:-:*:*:*:*:*:*:* |