CVE-2018-4833 Information
Description
A vulnerability has been identified in RFID 181-EIP (All versions) RUGGEDCOM Win (V4.4 V4.5 V5.0 and V5.1) SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions V5.2.3) SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions V5.4.1) SCALANCE X-200RNA switch family (All versions V3.2.6) SCALANCE X-300 switch family (incl. SIPLUS NET variants) (All versions V4.1.3) SCALANCE X408 (All versions V4.1.3) SCALANCE X414 (All versions) SIMATIC RF182C (All versions). Unprivileged remote attackers located in the same local network segment (OSI Layer 2) could gain remote code execution on the affected products by sending a specially crafted DHCP response to a client’s DHCP request.
CVSS Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://cert-portal.siemens.com/productcert/pdf/ssa-181018.pdf
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: