Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-6920


Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers to bypass intended access restrictions via TCP traffic to port (1) 21 or (2) 23.


Published

2013-12-07T00:55:04.147

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System siemens sinamics_s\/g_family_firmware ≤ 4.6 Yes
Hardware siemens sinamics_g110 - Yes
Hardware siemens sinamics_g110d - Yes
Hardware siemens sinamics_g120 - Yes
Hardware siemens sinamics_g120c - Yes
Hardware siemens sinamics_g120d - Yes
Hardware siemens sinamics_g120p - Yes
Hardware siemens sinamics_g130 - Yes
Hardware siemens sinamics_g150 - Yes
Hardware siemens sinamics_g180 - Yes
Hardware siemens sinamics_s110 - Yes
Hardware siemens sinamics_s120 - Yes
Hardware siemens sinamics_s120cm - Yes
Hardware siemens sinamics_s150 - Yes

References