Vulnerabilities > CVE-2013-5709 - Numeric Errors vulnerability in Siemens products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware before 5.0.0 does not use a sufficient source of entropy for generating values of random numbers, which makes it easier for remote attackers to hijack sessions by predicting a value.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 2 | |
Hardware | 11 |
Common Weakness Enumeration (CWE)
References
- http://ics-cert.us-cert.gov/advisories/ICSA-13-254-01
- http://ics-cert.us-cert.gov/advisories/ICSA-13-254-01
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-850708.pdf
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-850708.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-850708.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-850708.pdf