CVE-2012-1799
The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate of authentication attempts, which makes it easie...
Affects 4 products across 1 vendor.
Software does not prove or insufficiently proves that the user is who they claim to be.
Show all 10
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
The Siemens Scalance S Security Module firewall models S602 V2, S612 V2, and S613 V2 with firmware versions prior to 2.3.0.3 are vulnerable to a brute-force attack due to the lack of rate limiting on authentication attempts. This vulnerability allows remote attackers to gain unauthorized access to the administrative interface, potentially leading to full control of the device.
BSID: BS-2012-GLOBAL-315286-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2012-1799?
What is the CVSS score for CVE-2012-1799?
Is CVE-2012-1799 actively exploited?
How do I remediate CVE-2012-1799?
What systems are affected by CVE-2012-1799?
What NERC-CIP standard applies to CVE-2012-1799?
What IEC 62443 requirement maps to CVE-2012-1799?
| CVE ID | CVE-2012-1799 |
|---|---|
| BSID | BS-2012-GLOBAL-315286-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 2012-04-18 |
| Last Modified | 2026-04-29 |
| ICS Relevance | 100% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.
Source: NIST NVD / MITRE CVE Database
Remote attackers can exploit this vulnerability by repeatedly attempting to guess the administrative password without any rate limiting in place. This can lead to successful authentication and subsequent control over the firewall, compromising the integrity and availability of the network.
Exploitation Likelihood: LOW
| Vendor | Product | Fixed Version |
|---|---|---|
| Siemens | Scalance S Firmware | — |
| Siemens | Scalance S602 | — |
| Siemens | Scalance S612 | — |
| Siemens | Scalance S613 | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement a rate-limiting mechanism on the web server to restrict the number of login attempts within a specified time frame. Additionally, enable account lockout after a certain number of failed login attempts.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 because it allows unauthorized access to the firewall, which could compromise the security of the electronic security perimeter.
This CVE maps to SR 7.6 as it involves the protection against unauthorized access to the device's management interfaces, which is critical for maintaining the security of the industrial control system.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | c7cc960761917016547abb9b61347ea14829190c19abb729b0dd414dbeb017085d3a9d068352f4cfac194a5347bcf7f6e1c01da3a7e1495972de3d3fcce6d6ff |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →