CVE-2013-6920
Summary
| CVE | CVE-2013-6920 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-12-07 00:55:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers to bypass intended access restrictions via TCP traffic to port (1) 21 or (2) 23. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS: 0.011610000 probability, percentile 0.786720000 (date 2026-04-29)
Problem Types: CWE-287 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Siemens | Sinamics G110 | - | All | All | All |
| Hardware | Siemens | Sinamics G110d | - | All | All | All |
| Hardware | Siemens | Sinamics G120 | - | All | All | All |
| Hardware | Siemens | Sinamics G120c | - | All | All | All |
| Hardware | Siemens | Sinamics G120d | - | All | All | All |
| Hardware | Siemens | Sinamics G120p | - | All | All | All |
| Hardware | Siemens | Sinamics G130 | - | All | All | All |
| Hardware | Siemens | Sinamics G150 | - | All | All | All |
| Hardware | Siemens | Sinamics G180 | - | All | All | All |
| Hardware | Siemens | Sinamics S110 | - | All | All | All |
| Hardware | Siemens | Sinamics S120 | - | All | All | All |
| Hardware | Siemens | Sinamics S120cm | - | All | All | All |
| Hardware | Siemens | Sinamics S150 | - | All | All | All |
| Operating System | Siemens | Sinamics S/g Family Firmware | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cert-portal.siemens.com/productcert/pdf/ssa-742938.pdf | af854a3a-2127-422b-91ae-364da2661108 | cert-portal.siemens.com | |
| Siemens | af854a3a-2127-422b-91ae-364da2661108 | www.siemens.com | Vendor Advisory |
| Siemens SINAMICS S/G Authentication Bypass Vulnerability | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.