CVE-2013-6920
https://notcve.org/view.php?id=CVE-2013-6920
Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers to bypass intended access restrictions via TCP traffic to port (1) 21 or (2) 23. Los controladores Siemens SINAMICS S/G con firmware anterior a 4.6.11 no requiere autenticación para sesiones FTP y TELNET, lo que permite a atacantes remotos evadir restricciones de acceso intencionadas a través de trafico TCP al puerto (1) 21 o (2) 23. • http://ics-cert.us-cert.gov/advisories/ICSA-13-338-01 http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-742938.pdf https://cert-portal.siemens.com/productcert/pdf/ssa-742938.pdf • CWE-287: Improper Authentication •