CVE Vulnerabilities

CVE-2012-1799

Improper Authentication

Published: Apr 18, 2012 | Modified: Dec 06, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Scalance_s_firmware Siemens * 2.3.0 (including)
Scalance_s_firmware Siemens 2.1.0 (including) 2.1.0 (including)
Scalance_s_firmware Siemens 2.2.0 (including) 2.2.0 (including)

Potential Mitigations

References