8.3

CVE-2013-5709

The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware before 5.0.0 does not use a sufficient source of entropy for generating values of random numbers, which makes it easier for remote attackers to hijack sessions by predicting a value.

Data is provided by the National Vulnerability Database (NVD)
SiemensScalance X-200 Version-
SiemensScalance X-200rna Version-
SiemensScalance X201-3p Irt Version- Update- Editionpro
SiemensScalance X202-2p Irt Version- Update- Editionpro
SiemensScalance X204irt Version-
SiemensScalance X204irt Version- Update- Editionpro
SiemensScalance Xf-200 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.18% 0.837
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.3 8.6 8.5
AV:N/AC:M/Au:N/C:P/I:P/A:C