CVE-2013-3634

UnknownEPSS 1.44%

Last modified

CVE-2013-3634 is a vulnerability of currently unknown severity. A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V4.5.0 for CVE-2013-3634), SCALANCE X-200IRT switch family (incl. EPSS estimates a 1.44% chance of exploitation in the next 30 days.

Description

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V4.5.0 for CVE-2013-3634), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.1.0). The implementation of SNMPv3 does not check the user credentials sufficiently. Therefore, an attacker is able to execute SNMP commands without correct credentials.

Metrics

EPSS Probability
1.44%

69.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SiemensScalance X200irt Firmware<= 5.0.0
SiemensScalance X200-4p IrtAll versions
SiemensScalance X201-3p IrtAll versions
SiemensScalance X202-2irtAll versions
SiemensScalance X202-2p IrtAll versions
SiemensScalance X204irtAll versions
SiemensScalance Xf204irtAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-3634?
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V4.5.0 for CVE-2013-3634), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.1.0). The implementation of SNMPv3 does not check the user credentials sufficiently. Therefore, an attacker is able to execute SNMP commands without correct credentials.
How severe is CVE-2013-3634?
Severity scoring for CVE-2013-3634 is pending analysis. The EPSS model estimates a 1.44% probability of exploitation in the next 30 days.
How do I fix CVE-2013-3634?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2013-3634?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST