2025-04-11 02:06:08 +00:00

185 lines
6.1 KiB
JSON

{
"id": "CVE-2013-6920",
"sourceIdentifier": "cve@mitre.org",
"published": "2013-12-07T00:55:04.147",
"lastModified": "2025-04-11T00:51:21.963",
"vulnStatus": "Deferred",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers to bypass intended access restrictions via TCP traffic to port (1) 21 or (2) 23."
},
{
"lang": "es",
"value": "Los controladores Siemens SINAMICS S/G con firmware anterior a 4.6.11 no requiere autenticaci\u00f3n para sesiones FTP y TELNET, lo que permite a atacantes remotos evadir restricciones de acceso intencionadas a trav\u00e9s de trafico TCP al puerto (1) 21 o (2) 23."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"baseScore": 10.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:siemens:sinamics_s\\/g_family_firmware:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.6",
"matchCriteriaId": "F15BC1E1-45E3-44F0-BD41-E7A73FB33662"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:h:siemens:sinamics_g110:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E5ADF0BB-01FA-4FE4-BF4D-D33A6C5DAAFD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:h:siemens:sinamics_g110d:-:*:*:*:*:*:*:*",
"matchCriteriaId": "5CE4257F-7262-4CC0-A874-374106B4B2C8"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:h:siemens:sinamics_g120:-:*:*:*:*:*:*:*",
"matchCriteriaId": "61A60DCE-384B-43A4-A669-973FB8ECA932"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:h:siemens:sinamics_g120c:-:*:*:*:*:*:*:*",
"matchCriteriaId": "909DED2E-4CA6-4A07-B924-797260FDE2E4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:h:siemens:sinamics_g120d:-:*:*:*:*:*:*:*",
"matchCriteriaId": "75ED7DEA-67F8-4971-A076-79AF82026FD0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:h:siemens:sinamics_g120p:-:*:*:*:*:*:*:*",
"matchCriteriaId": "21FAA04F-FBE9-4EFA-BE79-1EAFF47A20D3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:h:siemens:sinamics_g130:-:*:*:*:*:*:*:*",
"matchCriteriaId": "373DBE44-AC28-4D04-93BB-35CD8C60E899"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:h:siemens:sinamics_g150:-:*:*:*:*:*:*:*",
"matchCriteriaId": "2296CA65-0E89-4BCB-8003-E7212BF1F585"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:h:siemens:sinamics_g180:-:*:*:*:*:*:*:*",
"matchCriteriaId": "EC515520-BB04-4849-ACE8-87ED5D591454"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:h:siemens:sinamics_s110:-:*:*:*:*:*:*:*",
"matchCriteriaId": "6218802E-D3B1-4197-A6B5-7343A50F7D88"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:h:siemens:sinamics_s120:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E5A824BD-935F-4E53-8313-C5544B0489C7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:h:siemens:sinamics_s120cm:-:*:*:*:*:*:*:*",
"matchCriteriaId": "C0ECF745-CE82-42C6-9EA0-12FBD89F6220"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:h:siemens:sinamics_s150:-:*:*:*:*:*:*:*",
"matchCriteriaId": "0D48682C-A39D-4A09-B904-50FA64A9D2A5"
}
]
}
]
}
],
"references": [
{
"url": "http://ics-cert.us-cert.gov/advisories/ICSA-13-338-01",
"source": "cve@mitre.org",
"tags": [
"US Government Resource"
]
},
{
"url": "http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-742938.pdf",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-742938.pdf",
"source": "cve@mitre.org"
},
{
"url": "http://ics-cert.us-cert.gov/advisories/ICSA-13-338-01",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"US Government Resource"
]
},
{
"url": "http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-742938.pdf",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-742938.pdf",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}