CVE-2013-4781

CRITICAL

core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to execute arbitr...

Affects 2 products across 1 vendor.

BCS8.26
CVSS 2.010.0
EPSS2.8%
Percentile86th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-78: OS Command Injection

Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.

Related Attack Patterns (CAPEC)
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-78
CAPEC-108 Command Line Execution through SQL Injection
via CWE-78
CAPEC-6 Argument Injection
via CWE-78
CAPEC-15 Command Delimiters
via CWE-78
CAPEC-88 OS Command Injection
via CWE-78

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

CVE-2013-4781 affects the core/getLog.php script on Siemens Enterprise OpenScape Branch and OpenScape SBC appliances, allowing remote attackers to execute arbitrary commands. The vulnerability has a CVSS score of 10.0, indicating critical severity, but the EPSS score suggests a low likelihood of exploitation in the wild.

BSID: BS-2013-GLOBAL-095626-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2013-4781?
CVE-2013-4781 affects the core/getLog.php script on Siemens Enterprise OpenScape Branch and OpenScape SBC appliances, allowing remote attackers to execute arbitrary commands. The vulnerability has a CVSS score of 10.0, indicating critical severity, but the EPSS score suggests a low likelihood of exploitation in the wild.
What is the CVSS score for CVE-2013-4781?
CVE-2013-4781 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 2.8%.
Is CVE-2013-4781 actively exploited?
No confirmed active exploitation of CVE-2013-4781 as of 2026-09-25.
How do I remediate CVE-2013-4781?
Priority: MEDIUM.
What systems are affected by CVE-2013-4781?
CVE-2013-4781 affects: Siemens, Siemens.
What NERC-CIP standard applies to CVE-2013-4781?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 as it allows unauthorized access to the control center, which could compromise the security of the electronic security perimeter.
What IEC 62443 requirement maps to CVE-2013-4781?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves a vulnerability that could allow an attacker to gain unauthorized access to the system, which is a critical security concern for ICS environments.
Vulnerability Details
CVE IDCVE-2013-4781
BSIDBS-2013-GLOBAL-095626-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2013-07-18
Last Modified2026-06-16
ICS Relevance90%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to execute arbitrary commands via unspecified vectors.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability exists in the core/getLog.php script, which can be exploited by remote attackers without authentication to execute arbitrary commands on the affected devices. This could lead to full system compromise, data exfiltration, and further lateral movement within the network.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Siemens Openscape Session Border Controller —
Siemens Enterprise Openscape Branch —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 4819 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Compensating Controls — AI-drafted, review before deploying MEDIUM CONFIDENCE

Implement strict input validation and sanitization for all web requests, especially those involving the core/getLog.php script. Consider deploying a Web Application Firewall (WAF) to monitor and block suspicious traffic.

SURICATA RULE
alert tcp any any -> any any (msg:"CVE-2013-4781 - Siemens OpenScape Remote Command Execution Attempt"; content:"/core/getLog.php"; http_uri; content:"cmd="; http_client_body; sid:9100020; rev:1;)
NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 as it allows unauthorized access to the control center, which could compromise the security of the electronic security perimeter.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves a vulnerability that could allow an attacker to gain unauthorized access to the system, which is a critical security concern for ICS environments.

Drafted by AI and not validated for your network. Test in an isolated environment before any production deployment. Compensating control only - does not replace vendor patch.

AI Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash7e4929abbb374d5eb461ec3ed9a75209fe0f288f3992b068a4a9fab52af8f43d719f7e46169f3898cbf574136a088710cb526b1870c041b66cfaa5a72b73dc9c
Related CVEs affecting Siemens
CVE-2007-1917 10.0 Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library... CVE-2008-6916 10.0 Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to... CVE-2008-6993 10.0 Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allo... CVE-2011-4514 10.0 The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC... CVE-2013-5944 10.0 The integrated web server on Siemens SCALANCE X-200 switches with firmware be...
View all Siemens CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →