CVE Vulnerabilities

CVE-2013-5709

Published: Sep 17, 2013 | Modified: Feb 10, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
8.3 HIGH
AV:N/AC:M/Au:N/C:P/I:P/A:C
RedHat/V2
RedHat/V3
Ubuntu

The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware before 5.0.0 does not use a sufficient source of entropy for generating values of random numbers, which makes it easier for remote attackers to hijack sessions by predicting a value.

Affected Software

Name Vendor Start Version End Version
Scalance_x-200_series_firmware Siemens * 4.4 (including)
Scalance_x-200_series_firmware Siemens 4.3 (including) 4.3 (including)

References