CVE-2008-6993

CRITICAL

Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allows remote attackers to conduct unauthorized activities. NOTE: the provenance of this information is unknown; the details...

Affects 1 product across 1 vendor.

BCS7.98
CVSS 2.010.0
EPSS1.9%
Percentile78th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-310: Cryptographic Issues

Broad class covering misuse of cryptography: weak algorithms, insufficient key length, improper certificate validation.

◆ SAGE Intelligence — CITED Relevance Research Team

The Siemens Gigaset WLAN Camera 1.27 is vulnerable to unauthorized access due to an insecure default password, allowing remote attackers to perform unauthorized activities. This vulnerability has a CVSS score of 10.0, indicating critical severity.

BSID: BS-2009-GLOBAL-311748-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2008-6993?
The Siemens Gigaset WLAN Camera 1.27 is vulnerable to unauthorized access due to an insecure default password, allowing remote attackers to perform unauthorized activities. This vulnerability has a CVSS score of 10.0, indicating critical severity.
What is the CVSS score for CVE-2008-6993?
CVE-2008-6993 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 1.9%.
Is CVE-2008-6993 actively exploited?
No confirmed active exploitation of CVE-2008-6993 as of 2026-05-30.
How do I remediate CVE-2008-6993?
Priority: MEDIUM.
What systems are affected by CVE-2008-6993?
CVE-2008-6993 affects: Siemens.
What NERC-CIP standard applies to CVE-2008-6993?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 because it involves unauthorized access to a critical asset, which could compromise the security of the control system.
What IEC 62443 requirement maps to CVE-2008-6993?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves the protection against unauthorized access to devices, which is essential for maintaining the security of industrial control systems.
Vulnerability Details
CVE IDCVE-2008-6993
BSIDBS-2009-GLOBAL-311748-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2009-08-19
Last Modified2026-04-23
ICS Relevance75%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allows remote attackers to conduct unauthorized activities. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The attack vector is network-based, requiring no authentication. An attacker can exploit the insecure default password to gain unauthorized access to the camera, potentially leading to full control over the device, including viewing live feeds, changing settings, and performing other malicious actions.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Siemens Gigaset Wlan Camera
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 6191 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strong access controls and change default passwords immediately. Use network segmentation to isolate the camera from critical systems.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 because it involves unauthorized access to a critical asset, which could compromise the security of the control system.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves the protection against unauthorized access to devices, which is essential for maintaining the security of industrial control systems.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashc8bef7479899c110fe54355c0ee5e534a2f49b86e0d106df107796a80fc4d770362bce8e82a6053c00e05ddbad4e116be62a56ff2e15e2efe7efe8df303e94aa
Related CVEs affecting Siemens
CVE-2025-40805 10.0 Affected devices do not properly enforce user authentication on specific API ... CVE-2000-0964 10.0 Buffer overflow in the web administration service for the HiNet LP5100 IP-pho... CVE-2007-1916 10.0 Buffer overflow in the RFC_START_GUI function in the SAP RFC Library 6.40 and... CVE-2007-1917 10.0 Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library... CVE-2015-1448 10.0 The integrated management service on Siemens Ruggedcom WIN51xx devices with f...
View all Siemens CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →