Unauthorized Access in Siemens SINAMICS S/G Controllers
CVE-2013-6920

Currently unrated

Key Information:

Vendor
Siemens
Vendor
CVE Published:
7 December 2013

Summary

Siemens SINAMICS S/G controllers with firmware prior to version 4.6.11 are susceptible to an improper authentication vulnerability that permits remote attackers to bypass authentication for FTP and TELNET sessions. This allows potentially malicious actors to gain unauthorized access via TCP traffic directed to ports 21 and 23, thus compromising the security posture of affected systems. Users of these controllers are strongly advised to apply the latest firmware updates to mitigate this risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.