The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware before 5.0.0 does not use a sufficient source of entropy for generating values of random numbers, which makes it easier for remote attackers to hijack sessions by predicting a value.

Project Subscriptions

Vendors Products
Siemens Subscribe
Scalance X-200 Subscribe
Scalance X-200 Series Firmware Subscribe
Scalance X-200rna Subscribe
Scalance X200-4p Irt Subscribe
Scalance X201-3p Irt Subscribe
Scalance X202-2irt Subscribe
Scalance X202-2p Irt Subscribe
Scalance X204irt Subscribe
Scalance Xf-200 Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2013-5546 The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware before 5.0.0 does not use a sufficient source of entropy for generating values of random numbers, which makes it easier for remote attackers to hijack sessions by predicting a value.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T17:22:31.062Z

Reserved: 2013-09-06T00:00:00.000Z

Link: CVE-2013-5709

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2013-09-17T12:04:28.820

Modified: 2025-04-11T00:51:21.963

Link: CVE-2013-5709

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses