// For flags

CVE-2013-3633

 

Severity Score

8.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V4.5.0 for CVE-2013-3634), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.1.0). The user privileges for the web interface are only enforced on client side and not properly verified on server side. Therefore, an attacker is able to execute privileged commands using an unprivileged account.

Se ha identificado una vulnerabilidad en la familia de conmutadores SCALANCE X-200 (incluidas las variantes SIPLUS NET) (Versiones anteriores a la versión V5.0.0 para CVE-2013-3633 y versiones anteriores a la versión V4.5.0 para CVE-2013-3634), conmutador SCALANCE X-200IRT familia (incluidas las variantes SIPLUS NET) (Todas las versiones anteriores a la versión V5.1.0). Los privilegios de usuario para la interfaz web solo se aplican en el lado del cliente y no se verifican adecuadamente en el lado del servidor. Por lo tanto, un atacante puede ejecutar comandos con privilegios utilizando una cuenta sin privilegios.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-05-22 CVE Reserved
  • 2013-05-24 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Siemens
Search vendor "Siemens"
Scalance X200irt Firmware
Search vendor "Siemens" for product "Scalance X200irt Firmware"
<= 5.0.0
Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0"
-
Affected
in Siemens
Search vendor "Siemens"
Scalance X200-4p Irt
Search vendor "Siemens" for product "Scalance X200-4p Irt"
--
Affected
Siemens
Search vendor "Siemens"
Scalance X200irt Firmware
Search vendor "Siemens" for product "Scalance X200irt Firmware"
<= 5.0.0
Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0"
-
Affected
in Siemens
Search vendor "Siemens"
Scalance X201-3p Irt
Search vendor "Siemens" for product "Scalance X201-3p Irt"
--
Affected
Siemens
Search vendor "Siemens"
Scalance X200irt Firmware
Search vendor "Siemens" for product "Scalance X200irt Firmware"
<= 5.0.0
Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0"
-
Affected
in Siemens
Search vendor "Siemens"
Scalance X201-3p Irt
Search vendor "Siemens" for product "Scalance X201-3p Irt"
-pro
Affected
Siemens
Search vendor "Siemens"
Scalance X200irt Firmware
Search vendor "Siemens" for product "Scalance X200irt Firmware"
<= 5.0.0
Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0"
-
Affected
in Siemens
Search vendor "Siemens"
Scalance X202-2irt
Search vendor "Siemens" for product "Scalance X202-2irt"
--
Affected
Siemens
Search vendor "Siemens"
Scalance X200irt Firmware
Search vendor "Siemens" for product "Scalance X200irt Firmware"
<= 5.0.0
Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0"
-
Affected
in Siemens
Search vendor "Siemens"
Scalance X202-2p Irt
Search vendor "Siemens" for product "Scalance X202-2p Irt"
--
Affected
Siemens
Search vendor "Siemens"
Scalance X200irt Firmware
Search vendor "Siemens" for product "Scalance X200irt Firmware"
<= 5.0.0
Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0"
-
Affected
in Siemens
Search vendor "Siemens"
Scalance X202-2p Irt
Search vendor "Siemens" for product "Scalance X202-2p Irt"
-pro
Affected
Siemens
Search vendor "Siemens"
Scalance X200irt Firmware
Search vendor "Siemens" for product "Scalance X200irt Firmware"
<= 5.0.0
Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0"
-
Affected
in Siemens
Search vendor "Siemens"
Scalance X204irt
Search vendor "Siemens" for product "Scalance X204irt"
--
Affected
Siemens
Search vendor "Siemens"
Scalance X200irt Firmware
Search vendor "Siemens" for product "Scalance X200irt Firmware"
<= 5.0.0
Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0"
-
Affected
in Siemens
Search vendor "Siemens"
Scalance X204irt
Search vendor "Siemens" for product "Scalance X204irt"
-pro
Affected
Siemens
Search vendor "Siemens"
Scalance X200irt Firmware
Search vendor "Siemens" for product "Scalance X200irt Firmware"
<= 5.0.0
Search vendor "Siemens" for product "Scalance X200irt Firmware" and version " <= 5.0.0"
-
Affected
in Siemens
Search vendor "Siemens"
Scalance Xf204irt
Search vendor "Siemens" for product "Scalance Xf204irt"
--
Affected