CVE-2013-4651

Siemens Scalance W7xx devices with firmware before 4.5.4 use the same hardcoded X.509 certificate across different customers' installations, which makes it easier for remote attackers to conduct man-in-the-middle attacks against SSL sessions by leveraging the certificate's trust relationship.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:scalance_w700_series_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:siemens:scalance_w786-1pro:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w786-2pro:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w747-1rr:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w786-3pro:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w784-1rr:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w788-2rr:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w746-1pro:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w744-1:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w746-1:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w747-1:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w788-1pro:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w788-2pro:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w786-2rr:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w788-1rr:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w784-1:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w744-1pro:-:*:*:*:*:*:*:*

Information

Published : 2013-08-01 06:32

Updated : 2013-08-01 06:32


NVD link : CVE-2013-4651

Mitre link : CVE-2013-4651


JSON object : View

CWE
CWE-255

Credentials Management Errors

Advertisement

dedicated server usa

Products Affected

siemens

  • scalance_w786-1pro
  • scalance_w746-1pro
  • scalance_w786-3pro
  • scalance_w788-2pro
  • scalance_w784-1rr
  • scalance_w788-1pro
  • scalance_w784-1
  • scalance_w700_series_firmware
  • scalance_w788-2rr
  • scalance_w786-2pro
  • scalance_w788-1rr
  • scalance_w744-1pro
  • scalance_w747-1
  • scalance_w747-1rr
  • scalance_w786-2rr
  • scalance_w744-1
  • scalance_w746-1