CVE-2013-5709 describes a critical vulnerability in the authentication implementation of Siemens SCALANCE X-200 series switches with firmware older than 5.0.0. The flaw stems from insufficient entropy in random number generation, making session hijacking feasible for remote attackers. With a CVSS score of 8.3, this vulnerability is highly severe, allowing unauthenticated remote attackers to compromise confidentiality, integrity, and availability with moderate attack complexity. Despite its age and high severity, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, suggesting it is not actively exploited. However, it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.4CPE matchmatch criteria | cpe:2.3:o:siemens:scalance_x-200_series_firmware:*:*:*:*:*:*:*:* | ||
4.3CPE matchmatch criteria | cpe:2.3:o:siemens:scalance_x-200_series_firmware:4.3:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:siemens:scalance_x-200:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:siemens:scalance_x-200rna:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:siemens:scalance_x200-4p_irt:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.