Lucene search

K
nvd[email protected]NVD:CVE-2013-5709
HistorySep 17, 2013 - 12:04 p.m.

CVE-2013-5709

2013-09-1712:04:28
CWE-189
web.nvd.nist.gov
4

8.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:P/I:P/A:C

6.8 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

80.7%

The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware before 5.0.0 does not use a sufficient source of entropy for generating values of random numbers, which makes it easier for remote attackers to hijack sessions by predicting a value.

Affected configurations

NVD
Node
siemensscalance_x-200_series_firmwareRange4.4
OR
siemensscalance_x-200_series_firmwareMatch4.3
AND
siemensscalance_x-200Match-
OR
siemensscalance_x-200rnaMatch-
OR
siemensscalance_x200-4p_irtMatch-
OR
siemensscalance_x201-3p_irtMatch-
OR
siemensscalance_x201-3p_irtMatch--pro
OR
siemensscalance_x202-2irtMatch-
OR
siemensscalance_x202-2p_irtMatch-
OR
siemensscalance_x202-2p_irtMatch--pro
OR
siemensscalance_x204irtMatch-
OR
siemensscalance_x204irtMatch--pro
OR
siemensscalance_xf-200Match-

8.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:P/I:P/A:C

6.8 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

80.7%

Related for NVD:CVE-2013-5709