CVE-2013-5944
The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which...
Affects 3 products across 1 vendor.
Software does not prove or insufficiently proves that the user is who they claim to be.
Show all 10
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
CVE-2013-5944 affects the integrated web server on Siemens SCALANCE X-200 and X-200IRT switches, allowing remote attackers to perform administrative actions without proper authentication. This vulnerability has a CVSS score of 10.0, indicating critical severity.
BSID: BS-2013-GLOBAL-096107-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2013-5944?
What is the CVSS score for CVE-2013-5944?
Is CVE-2013-5944 actively exploited?
How do I remediate CVE-2013-5944?
What systems are affected by CVE-2013-5944?
What NERC-CIP standard applies to CVE-2013-5944?
What IEC 62443 requirement maps to CVE-2013-5944?
| CVE ID | CVE-2013-5944 |
|---|---|
| BSID | BS-2013-GLOBAL-096107-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 2013-10-03 |
| Last Modified | 2026-06-16 |
| ICS Relevance | 100% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which allows remote attackers to perform administrative actions via requests to the management interface.
Source: NIST NVD / MITRE CVE Database
The vulnerability arises from the web server's failure to enforce authentication requirements, enabling remote attackers to send unauthenticated requests to the management interface and execute administrative functions.
Exploitation Likelihood: LOW
| Vendor | Product | Fixed Version |
|---|---|---|
| Siemens | Scalance X-200 Series Firmware | — |
| Siemens | Scalance X-200 | — |
| Siemens | Scalance X-200Irt | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strict access control policies and monitor network traffic for unauthorized administrative activities.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. A network rule is only drafted when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 by allowing unauthorized access to the management interface, which could compromise the security of the electronic security perimeter.
This CVE maps to SR 7.6 as it involves a failure in the enforcement of authentication mechanisms, which is crucial for maintaining the security of industrial control systems.
Drafted by AI and not validated for your network. Test in an isolated environment before any production deployment. Compensating control only - does not replace vendor patch.
AI Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 4584cc0a4ba8bbbfd09cd95dc248dad749c63e658d50aa72a5355d243817b47a1e4ebcb8b92ea5c97a18d1615215af28912f1f9e0e9c223e612e3a14c0136306 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Create a free account →