CVE-2015-1049: Input Validation
Published Feb 2, 2015
·Updated
The web server on Siemens SCALANCE X-200IRT switches with firmware before 5.2.0 allows remote attackers to hijack sessions via unspecified vectors.
Affected Software
10 affected components
Siemens Scalance X-200 Series Firmware<=5.1.1
Siemens SCALANCE X201-3P IRT PRO
Siemens Scalance X201-3pirt
Siemens Scalance X202-2irt
Siemens Scalance X202-2p Irt
Siemens SCALANCE X202-2P IRT PRO
Siemens Scalance X202-4p Irt
Siemens Scalance X204irt
Siemens Scalance X204irt Pro
Siemens Scalance Xf204irt
Event History
Feb 2, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1049?
CVE-2015-1049 has a medium severity rating due to the potential for unauthorized session hijacking.
2
How do I fix CVE-2015-1049?
To fix CVE-2015-1049, update the firmware of affected Siemens SCALANCE X-200IRT switches to version 5.2.0 or later.
3
What type of vulnerability is CVE-2015-1049?
CVE-2015-1049 is a remote session hijacking vulnerability in Siemens SCALANCE X-200IRT switches.
4
Which devices are affected by CVE-2015-1049?
CVE-2015-1049 affects Siemens SCALANCE X-200IRT switches running firmware versions prior to 5.2.0.
5
Can CVE-2015-1049 be exploited locally?
No, CVE-2015-1049 is specifically a remote vulnerability and does not require local access to the devices.