10

CVE-2012-1799

The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Scalance S Firmware Version <= 2.3.0
Siemens ≫ Scalance S Firmware Version 2.1.0
Siemens ≫ Scalance S Firmware Version 2.2.0
Siemens ≫ Scalance S602 Version v2
Siemens ≫ Scalance S612 Version v2
Siemens ≫ Scalance S613 Version v2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.07% 0.912
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://osvdb.org/81033
http://support.automation.siemens.com/WW/view/en/59869684
http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-268149.pdf
Vendor Advisory
http://www.us-cert.gov/control_systems/pdf/ICSA-12-102-05.pdf
US Government Resource