CVE-2013-4781
core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to execute arbitr...
Affects 2 products across 1 vendor.
Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
CVE-2013-4781 affects the core/getLog.php script on Siemens Enterprise OpenScape Branch and OpenScape SBC appliances, allowing remote attackers to execute arbitrary commands. The vulnerability has a CVSS score of 10.0, indicating critical severity, but the EPSS score suggests a low likelihood of exploitation in the wild.
BSID: BS-2013-GLOBAL-095626-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2013-4781?
What is the CVSS score for CVE-2013-4781?
Is CVE-2013-4781 actively exploited?
How do I remediate CVE-2013-4781?
What systems are affected by CVE-2013-4781?
What NERC-CIP standard applies to CVE-2013-4781?
What IEC 62443 requirement maps to CVE-2013-4781?
| CVE ID | CVE-2013-4781 |
|---|---|
| BSID | BS-2013-GLOBAL-095626-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 2013-07-18 |
| Last Modified | 2026-06-16 |
| ICS Relevance | 90% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to execute arbitrary commands via unspecified vectors.
Source: NIST NVD / MITRE CVE Database
The vulnerability exists in the core/getLog.php script, which can be exploited by remote attackers without authentication to execute arbitrary commands on the affected devices. This could lead to full system compromise, data exfiltration, and further lateral movement within the network.
Exploitation Likelihood: LOW
| Vendor | Product | Fixed Version |
|---|---|---|
| Siemens | Openscape Session Border Controller | — |
| Siemens | Enterprise Openscape Branch | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strict input validation and sanitization for all web requests, especially those involving the core/getLog.php script. Consider deploying a Web Application Firewall (WAF) to monitor and block suspicious traffic.
This CVE violates CIP-007-R2 as it allows unauthorized access to the control center, which could compromise the security of the electronic security perimeter.
This CVE maps to SR 7.6 because it involves a vulnerability that could allow an attacker to gain unauthorized access to the system, which is a critical security concern for ICS environments.
Drafted by AI and not validated for your network. Test in an isolated environment before any production deployment. Compensating control only - does not replace vendor patch.
AI Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 7e4929abbb374d5eb461ec3ed9a75209fe0f288f3992b068a4a9fab52af8f43d719f7e46169f3898cbf574136a088710cb526b1870c041b66cfaa5a72b73dc9c |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Create a free account →