CVE-2013-3633
Last modified
CVE-2013-3633 is a vulnerability of currently unknown severity. A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V4.5.0 for CVE-2013-3634), SCALANCE X-200IRT switch family (incl. EPSS estimates a 1.20% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V4.5.0 for CVE-2013-3634), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.1.0). The user privileges for the web interface are only enforced on client side and not properly verified on server side. Therefore, an attacker is able to execute privileged commands using an unprivileged account.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Scalance X200irt Firmware | <= 5.0.0 |
| Siemens | Scalance X200-4p Irt | All versions |
| Siemens | Scalance X201-3p Irt | All versions |
| Siemens | Scalance X202-2irt | All versions |
| Siemens | Scalance X202-2p Irt | All versions |
| Siemens | Scalance X204irt | All versions |
| Siemens | Scalance Xf204irt | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-3633?
How severe is CVE-2013-3633?
How do I fix CVE-2013-3633?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-3627FrameworkService.exe in McAfee Framework Service in McAfee M…
- CVE-2013-3628Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerabilit…8.8
- CVE-2013-3629ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution8.8
- CVE-2013-3630Moodle through 2.5.2 allows remote authenticated administrat…
- CVE-2013-3631NAS4Free 9.1.0.1.804 and earlier allows remote authenticated…
- CVE-2013-3632The Cron service in rpc.php in OpenMediaVault allows remote …8.8
- CVE-2013-3634A vulnerability has been identified in SCALANCE X-200 switch…
- CVE-2013-3635ProjectPier 0.8.8 has stored XSS5.4
- CVE-2013-3636ProjectPier 0.8.8 has a Remote Information Disclosure Weakne…5.4
- CVE-2013-3637ProjectPier 0.8.8 does not use the Secure flag for cookies5.4
- CVE-2013-3638SQL injection vulnerability in Boonex Dolphin before 7.1.3 a…8.8
- CVE-2013-3639Multiple cross-site scripting (XSS) vulnerabilities in Xaray…
Are you affected by CVE-2013-3633?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
