CVE-2018-4840
CVE-2018-4840
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
08 Mar 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions). The device engineering mechanism allows an unauthenticated remote user to upload a modified device configuration overwriting access authorization passwords.
Affected products
Siemens · DIGSI 4Siemens · EN100 Ethernet module DNP3 variantSiemens · EN100 Ethernet module IEC 104 variantSiemens · EN100 Ethernet module IEC 61850 variantSiemens · EN100 Ethernet module Modbus TCP variantSiemens · EN100 Ethernet module PROFINET IO variantWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →