CVE-2013-3633: Siemens Scalance x200-4p Irt
High severity, CVSS 8.0. EPSS: 1.2% chance of exploitation in the next 30 days.
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V4.5.0 for CVE-2013-3634), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.1.0). The user privileges for the web interface are only enforced on client side and not properly verified on server side. Therefore, an attacker is able to execute privileged commands using an unprivileged account.
Affected products
- Siemens Scalance x200-4p Irt
- Siemens Scalance x200irt Firmware: up to and including 5.0.0
- Siemens Scalance x201-3p Irt
- Siemens Scalance x202-2irt
- Siemens Scalance x202-2p Irt
- Siemens Scalance x204irt
- Siemens Scalance XF204IRT
Published 2013-05-24. Last modified 2026-06-16.