CVE-2013-6920: Critical severity Siemens Sinamics S\/g Family Firmware vulnerability
Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers to bypass intended access restrictions via TCP traffic to port (1) 21 or (2) 23.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Siemens SINAMICS S/G controllersto a version that resolves this vulnerability.Fixed in 4.6.11 - Compensating control
Restrict network access to TCP ports 21 (FTP) and 23 (TELNET) so remote clients cannot reach the controllers until authentication is present.
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6920?
CVE-2013-6920 is classified as a high severity vulnerability due to the lack of authentication for FTP and TELNET sessions.
How do I fix CVE-2013-6920?
To fix CVE-2013-6920, users should upgrade to firmware version 4.6.11 or later for affected Siemens SINAMICS S/G controllers.
What devices are affected by CVE-2013-6920?
CVE-2013-6920 affects Siemens SINAMICS S/G controllers with firmware versions prior to 4.6.11, including models like G110, G120, and others.
What risks does CVE-2013-6920 pose to my system?
CVE-2013-6920 allows remote attackers to bypass access restrictions, potentially compromising system integrity and security.
Is there a workaround for CVE-2013-6920?
There are no documented workarounds for CVE-2013-6920; the recommended action is to update to the patched firmware.