CVE-2012-1799

critical
Published 2012-04-18 · Modified 2026-04-29
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cret@cert.org — http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-268149.pdf

Application impact

VendorProductVersionsFixed
siemensscalance_s_firmware{"endIncluding":"2.3.0"}
siemensscalance_s_firmware2.1.0
siemensscalance_s_firmware2.2.0

References

CWEs

CWE-287

Verify integrity in audit chain (admin only). AS-IS.