CVE-2013-5944

CRITICAL

The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which...

Affects 3 products across 1 vendor.

BCS8.13
CVSS 2.010.0
EPSS3.2%
Percentile88th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-287: Improper Authentication

Software does not prove or insufficiently proves that the user is who they claim to be.

Related Attack Patterns (CAPEC)
CAPEC-57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
via CWE-287
CAPEC-633 Token Impersonation
via CWE-287
CAPEC-650 Upload a Web Shell to a Web Server
via CWE-287
CAPEC-194 Fake the Source of Data
via CWE-287
CAPEC-593 Session Hijacking
via CWE-287
Show all 10

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

CVE-2013-5944 affects the integrated web server on Siemens SCALANCE X-200 and X-200IRT switches, allowing remote attackers to perform administrative actions without proper authentication. This vulnerability has a CVSS score of 10.0, indicating critical severity.

BSID: BS-2013-GLOBAL-096107-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2013-5944?
CVE-2013-5944 affects the integrated web server on Siemens SCALANCE X-200 and X-200IRT switches, allowing remote attackers to perform administrative actions without proper authentication. This vulnerability has a CVSS score of 10.0, indicating critical severity.
What is the CVSS score for CVE-2013-5944?
CVE-2013-5944 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 3.2%.
Is CVE-2013-5944 actively exploited?
No confirmed active exploitation of CVE-2013-5944 as of 2026-09-25.
How do I remediate CVE-2013-5944?
Priority: MEDIUM.
What systems are affected by CVE-2013-5944?
CVE-2013-5944 affects: Siemens, Siemens, Siemens.
What NERC-CIP standard applies to CVE-2013-5944?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 by allowing unauthorized access to the management interface, which could compromise the security of the electronic security perimeter.
What IEC 62443 requirement maps to CVE-2013-5944?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 as it involves a failure in the enforcement of authentication mechanisms, which is crucial for maintaining the security of industrial control systems.
Vulnerability Details
CVE IDCVE-2013-5944
BSIDBS-2013-GLOBAL-096107-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2013-10-03
Last Modified2026-06-16
ICS Relevance100%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which allows remote attackers to perform administrative actions via requests to the management interface.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability arises from the web server's failure to enforce authentication requirements, enabling remote attackers to send unauthenticated requests to the management interface and execute administrative functions.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Siemens Scalance X-200 Series Firmware —
Siemens Scalance X-200 —
Siemens Scalance X-200Irt —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 4743 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Compensating Controls — AI-drafted, review before deploying MEDIUM CONFIDENCE

Implement strict access control policies and monitor network traffic for unauthorized administrative activities.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. A network rule is only drafted when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 by allowing unauthorized access to the management interface, which could compromise the security of the electronic security perimeter.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 as it involves a failure in the enforcement of authentication mechanisms, which is crucial for maintaining the security of industrial control systems.

Drafted by AI and not validated for your network. Test in an isolated environment before any production deployment. Compensating control only - does not replace vendor patch.

AI Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash4584cc0a4ba8bbbfd09cd95dc248dad749c63e658d50aa72a5355d243817b47a1e4ebcb8b92ea5c97a18d1615215af28912f1f9e0e9c223e612e3a14c0136306
Related CVEs affecting Siemens
CVE-2007-1917 10.0 Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library... CVE-2008-6916 10.0 Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to... CVE-2008-6993 10.0 Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allo... CVE-2011-4514 10.0 The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC... CVE-2013-4781 10.0 core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and Open...
View all Siemens CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →