CVE-2012-1799

CRITICAL

The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate of authentication attempts, which makes it easie...

Affects 4 products across 1 vendor.

BCS8.16
CVSS 2.010.0
EPSS5.1%
Percentile91th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-287: Improper Authentication

Software does not prove or insufficiently proves that the user is who they claim to be.

Related Attack Patterns (CAPEC)
CAPEC-57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
via CWE-287
CAPEC-633 Token Impersonation
via CWE-287
CAPEC-650 Upload a Web Shell to a Web Server
via CWE-287
CAPEC-194 Fake the Source of Data
via CWE-287
CAPEC-593 Session Hijacking
via CWE-287
Show all 10

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

The Siemens Scalance S Security Module firewall models S602 V2, S612 V2, and S613 V2 with firmware versions prior to 2.3.0.3 are vulnerable to a brute-force attack due to the lack of rate limiting on authentication attempts. This vulnerability allows remote attackers to gain unauthorized access to the administrative interface, potentially leading to full control of the device.

BSID: BS-2012-GLOBAL-315286-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2012-1799?
The Siemens Scalance S Security Module firewall models S602 V2, S612 V2, and S613 V2 with firmware versions prior to 2.3.0.3 are vulnerable to a brute-force attack due to the lack of rate limiting on authentication attempts. This vulnerability allows remote attackers to gain unauthorized access to the administrative interface, potentially leading to full control of the device.
What is the CVSS score for CVE-2012-1799?
CVE-2012-1799 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 5.1%.
Is CVE-2012-1799 actively exploited?
No confirmed active exploitation of CVE-2012-1799 as of 2026-05-30.
How do I remediate CVE-2012-1799?
Priority: MEDIUM. Advisory: http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-268149.pdf PSIRT: [email protected]
What systems are affected by CVE-2012-1799?
CVE-2012-1799 affects: Siemens, Siemens, Siemens, Siemens.
What NERC-CIP standard applies to CVE-2012-1799?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 because it allows unauthorized access to the firewall, which could compromise the security of the electronic security perimeter.
What IEC 62443 requirement maps to CVE-2012-1799?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 as it involves the protection against unauthorized access to the device's management interfaces, which is critical for maintaining the security of the industrial control system.
Vulnerability Details
CVE IDCVE-2012-1799
BSIDBS-2012-GLOBAL-315286-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2012-04-18
Last Modified2026-04-29
ICS Relevance100%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Remote attackers can exploit this vulnerability by repeatedly attempting to guess the administrative password without any rate limiting in place. This can lead to successful authentication and subsequent control over the firewall, compromising the integrity and availability of the network.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Siemens Scalance S Firmware
Siemens Scalance S602
Siemens Scalance S612
Siemens Scalance S613
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 5220 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement a rate-limiting mechanism on the web server to restrict the number of login attempts within a specified time frame. Additionally, enable account lockout after a certain number of failed login attempts.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 because it allows unauthorized access to the firewall, which could compromise the security of the electronic security perimeter.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 as it involves the protection against unauthorized access to the device's management interfaces, which is critical for maintaining the security of the industrial control system.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashc7cc960761917016547abb9b61347ea14829190c19abb729b0dd414dbeb017085d3a9d068352f4cfac194a5347bcf7f6e1c01da3a7e1495972de3d3fcce6d6ff
Related CVEs affecting Siemens
CVE-2024-45032 10.0 A vulnerability has been identified in Industrial Edge Management Pro (All ve... CVE-2026-56451 10.0 Siemens Opcenter X CVE-2000-0964 10.0 Buffer overflow in the web administration service for the HiNet LP5100 IP-pho... CVE-2007-1917 10.0 Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library... CVE-2025-40805 10.0 Affected devices do not properly enforce user authentication on specific API ...
View all Siemens CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →