← Vulnerability feed

Vulnerability record · CVE-2019-13924 · published 11 February 2020

CVE-2019-13924: Siemens scalance xc-200 firmware clickjacking vulnerability

Siemens · Scalance Xc 200 Firmware

A vulnerability has been identified in SCALANCE S602 (All versions < V4.1), SCALANCE S612 (All versions < V4.1), SCALANCE S623 (All versions < V4.1), SCALANCE S627-2M (All versions < V4.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < 5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < 4.1.3). The device does not send the X-Frame-Option Header in the administrative web interface, which makes it vulnerable to Clickjacking attacks. The security vulnerability could be exploited by an attacker that is able to trick an administrative user with a valid session on the target device into clicking on a website controlled by the attacker. The vulnerability could allow an attacker to perform administrative actions via the web interface.

5.4 CVSS 3.1 Medium EPSS 0.83% · top 44.3% CWE-693 · CWE-693CWE-1021 · Clickjacking
5.4CVSS 3.1 base score, v2 4.3
0.83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
8Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in SCALANCE S602 (All versions < V4.1), SCALANCE S612 (All versions < V4.1), SCALANCE S623 (All versions < V4.1), SCALANCE S627-2M (All versions < V4.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < 5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < 4.1.3). The device does not send the X-Frame-Option Header in the administrative web interface, which makes it vulnerable to Clickjacking attacks. The security vulnerability could be exploited by an attacker that is able to trick an administrative user with a valid session on the target device into clicking on a website controlled by the attacker. The vulnerability could allow an attacker to perform administrative actions via the web interface.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-13924 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2022-36323Siemens scalance m-800 firmware injection vulnerabilityAffected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject …EPSS 1.7%9.1CVE-2019-6569Siemens scalance x-200 firmware vulnerabilityThe monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network. An attac…EPSS 1.3%8.8CVE-2021-25667Siemens ruggedcom rm1224 firmware stack-based buffer overflow vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions >= V4.3 and < V6.4), SCALANCE…EPSS 0.86%8.8CVE-2017-12736Siemens scalance xb-200 firmware insecure default initialization vulnerabilityAfter initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain conditions. This could allow …EPSS 1.1%8.7CVE-2020-28400Siemens dk standard ethernet controller evaluation kit firmware allocation without limits vulnerabilityAffected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be t…EPSS 1.9%8.6CVE-2019-13933Siemens scalance x-200rna firmware missing authentication for critical function vulnerabilityA vulnerability has been identified in SCALANCE X204RNA (HSR), SCALANCE X204RNA (PRP), SCALANCE X204RNA EEC (HSR), SCALANCE X204RNA EEC (PRP), SCALAN…EPSS 1.4%8.6CVE-2019-10942Siemens scalance x-200 firmware uncontrolled resource consumption vulnerabilityA vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch fam…EPSS 1.4%7.8CVE-2012-1802Siemens scalance x414-3e firmware memory buffer overflow vulnerabilityBuffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC …EPSS 6.1%

Source: NIST National Vulnerability Database (record CVE-2019-13924), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.