ID

VAR-202010-1616


TITLE

Siemens X200 series industrial Ethernet switches have permissions and access control vulnerabilities

Trust: 0.6

sources: CNVD: CNVD-2020-61993

DESCRIPTION

Siemens is the world's leading technology company, relying on innovations in the fields of electrification, automation and digitalization to provide customers with solutions in the fields of power generation and transmission and distribution, infrastructure, industrial automation, drives and software. Siemens X200 series industrial Ethernet switches have permission and access control loopholes, which can be exploited by attackers to affect system availability.

Trust: 0.6

sources: CNVD: CNVD-2020-61993

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-61993

AFFECTED PRODUCTS

vendor:siemensmodel:series industrial ethernet switch seriesscope:eqversion:x200x200

Trust: 0.6

sources: CNVD: CNVD-2020-61993

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2020-61993
value: HIGH

Trust: 0.6

CNVD: CNVD-2020-61993
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2020-61993

EXTERNAL IDS

db:CNVDid:CNVD-2020-61993

Trust: 0.6

sources: CNVD: CNVD-2020-61993

SOURCES

db:CNVDid:CNVD-2020-61993

LAST UPDATE DATE

2022-05-04T09:46:12.895000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-61993date:2021-01-18T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-61993date:2020-10-31T00:00:00