A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V4.5.0 for CVE-2013-3634), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.1.0). The user privileges for the web interface are only enforced on client side and not properly verified on server side. Therefore, an attacker is able to execute privileged commands using an unprivileged account.

Project Subscriptions

Vendors Products
Siemens Subscribe
Scalance X200-4p Irt Subscribe
Scalance X200irt Firmware Subscribe
Scalance X201-3p Irt Subscribe
Scalance X202-2irt Subscribe
Scalance X202-2p Irt Subscribe
Scalance X204irt Subscribe
Scalance Xf204irt Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2013-3566 A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V4.5.0 for CVE-2013-3634), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.1.0). The user privileges for the web interface are only enforced on client side and not properly verified on server side. Therefore, an attacker is able to execute privileged commands using an unprivileged account.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T16:14:56.558Z

Reserved: 2013-05-22T00:00:00.000Z

Link: CVE-2013-3633

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2013-05-24T20:55:01.737

Modified: 2025-04-11T00:51:21.963

Link: CVE-2013-3633

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses