#VU24311 Missing Authentication for Critical Function in Siemens products - CVE-2019-13933
Published: January 15, 2020
SCALANCE X-200RNA
SCALANCE X-300
SCALANCE X-408
Siemens
Description
The vulnerability allows a remote attacker to violate access-control rules.
The vulnerability exists due to the affected system contains an authentication bypass vulnerability. A remote attacker can send a specially crafted GET request to specific uniform resource locator on the web configuration interface of the device and obtain sensitive information or change the device configuration.