CVE-2013-3633
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V4.5.0 for CVE-2013-3634), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.1.0). The user privileges for the web interface are only enforced on client side and not properly verified on server side. Therefore, an attacker is able to execute privileged commands using an unprivileged account.
Se ha identificado una vulnerabilidad en la familia de conmutadores SCALANCE X-200 (incluidas las variantes SIPLUS NET) (Versiones anteriores a la versión V5.0.0 para CVE-2013-3633 y versiones anteriores a la versión V4.5.0 para CVE-2013-3634), conmutador SCALANCE X-200IRT familia (incluidas las variantes SIPLUS NET) (Todas las versiones anteriores a la versión V5.1.0). Los privilegios de usuario para la interfaz web solo se aplican en el lado del cliente y no se verifican adecuadamente en el lado del servidor. Por lo tanto, un atacante puede ejecutar comandos con privilegios utilizando una cuenta sin privilegios.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-05-22 CVE Reserved
- 2013-05-24 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-170686.pdf | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Scalance X200irt Firmware Search vendor "Siemens" for product "Scalance X200irt Firmware" | <= 5.0.0 Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance X200-4p Irt Search vendor "Siemens" for product "Scalance X200-4p Irt" | - | - |
Affected
|
Siemens Search vendor "Siemens" | Scalance X200irt Firmware Search vendor "Siemens" for product "Scalance X200irt Firmware" | <= 5.0.0 Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance X201-3p Irt Search vendor "Siemens" for product "Scalance X201-3p Irt" | - | - |
Affected
|
Siemens Search vendor "Siemens" | Scalance X200irt Firmware Search vendor "Siemens" for product "Scalance X200irt Firmware" | <= 5.0.0 Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance X201-3p Irt Search vendor "Siemens" for product "Scalance X201-3p Irt" | - | pro |
Affected
|
Siemens Search vendor "Siemens" | Scalance X200irt Firmware Search vendor "Siemens" for product "Scalance X200irt Firmware" | <= 5.0.0 Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance X202-2irt Search vendor "Siemens" for product "Scalance X202-2irt" | - | - |
Affected
|
Siemens Search vendor "Siemens" | Scalance X200irt Firmware Search vendor "Siemens" for product "Scalance X200irt Firmware" | <= 5.0.0 Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance X202-2p Irt Search vendor "Siemens" for product "Scalance X202-2p Irt" | - | - |
Affected
|
Siemens Search vendor "Siemens" | Scalance X200irt Firmware Search vendor "Siemens" for product "Scalance X200irt Firmware" | <= 5.0.0 Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance X202-2p Irt Search vendor "Siemens" for product "Scalance X202-2p Irt" | - | pro |
Affected
|
Siemens Search vendor "Siemens" | Scalance X200irt Firmware Search vendor "Siemens" for product "Scalance X200irt Firmware" | <= 5.0.0 Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance X204irt Search vendor "Siemens" for product "Scalance X204irt" | - | - |
Affected
|
Siemens Search vendor "Siemens" | Scalance X200irt Firmware Search vendor "Siemens" for product "Scalance X200irt Firmware" | <= 5.0.0 Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance X204irt Search vendor "Siemens" for product "Scalance X204irt" | - | pro |
Affected
|
Siemens Search vendor "Siemens" | Scalance X200irt Firmware Search vendor "Siemens" for product "Scalance X200irt Firmware" | <= 5.0.0 Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance Xf204irt Search vendor "Siemens" for product "Scalance Xf204irt" | - | - |
Affected
|