ID

VAR-201803-2155


CVE

CVE-2018-4838


TITLE

plural Siemens Access control vulnerabilities in products

Trust: 0.8

sources: JVNDB: JVNDB-2018-002719

DESCRIPTION

A vulnerability has been identified in EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module DNP3 variant (All versions < V1.04), EN100 Ethernet module PROFINET IO variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions < V1.22). The web interface (TCP/80) of affected devices allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to older versions with known vulnerabilities. plural Siemens The product contains an access control vulnerability.Information may be tampered with. SIPROTEC 4, SIPROTEC Compact and Reyrolle equipment offer a wide range of centralized protection, control and automation functions for substations and other applications. Multiple Siemens EN100 Ethernet Modules are prone to an authentication-bypass vulnerability. An attacker can exploit this issue to bypass the authentication mechanism. This may aid in further attacks. A security vulnerability exists in the web interface (TCP/80) in several Siemens products

Trust: 2.7

sources: NVD: CVE-2018-4838 // JVNDB: JVNDB-2018-002719 // CNVD: CNVD-2018-04834 // BID: 103379 // IVD: e2e52650-39ab-11e9-ad8d-000c29342cb1 // VULHUB: VHN-134869

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: e2e52650-39ab-11e9-ad8d-000c29342cb1 // CNVD: CNVD-2018-04834

AFFECTED PRODUCTS

vendor:siemensmodel:en100 ethernet module dnp3scope:eqversion: -

Trust: 1.6

vendor:siemensmodel:en100 ethernet module modbus tcpscope:eqversion: -

Trust: 1.6

vendor:siemensmodel:en100 ethernet module profinet ioscope:eqversion: -

Trust: 1.6

vendor:siemensmodel:en100 ethernet module iec 104scope:eqversion: -

Trust: 1.6

vendor:siemensmodel:en100 ethernet module iec 61850scope:ltversion:4.30

Trust: 1.0

vendor:siemensmodel:en100 ethernet module dnp3scope: - version: -

Trust: 0.8

vendor:siemensmodel:en100 ethernet module iec 104scope: - version: -

Trust: 0.8

vendor:siemensmodel:en100 ethernet module iec 61850scope: - version: -

Trust: 0.8

vendor:siemensmodel:en100 ethernet module modbus tcpscope: - version: -

Trust: 0.8

vendor:siemensmodel:en100 ethernet module profinet ioscope: - version: -

Trust: 0.8

vendor:siemensmodel:iecscope:eqversion:61850<v4.30

Trust: 0.6

vendor:siemensmodel:profinet ioscope: - version: -

Trust: 0.6

vendor:siemensmodel:modbus tcpscope: - version: -

Trust: 0.6

vendor:siemensmodel:dnp3scope: - version: -

Trust: 0.6

vendor:siemensmodel:iecscope:eqversion:104

Trust: 0.6

vendor:siemensmodel:siprotec compactscope:eqversion:0

Trust: 0.3

vendor:siemensmodel:siprotecscope:eqversion:40

Trust: 0.3

vendor:siemensmodel:reyrollescope:eqversion:0

Trust: 0.3

vendor:siemensmodel:en100 ethernet module profinet ioscope:eqversion:0

Trust: 0.3

vendor:siemensmodel:en100 ethernet module modbus tcpscope:eqversion:0

Trust: 0.3

vendor:siemensmodel:en100 ethernet module iecscope:eqversion:618500

Trust: 0.3

vendor:siemensmodel:en100 ethernet module iecscope:eqversion:1040

Trust: 0.3

vendor:siemensmodel:en100 ethernet module dnp3scope:eqversion:0

Trust: 0.3

vendor:siemensmodel:en100 ethernet module iecscope:neversion:618504.30

Trust: 0.3

vendor:siemensmodel:iec siemens profinet io *siemens modbus tcp *siemens dnp3 *siemens iecscope:eqversion:61850104

Trust: 0.2

sources: IVD: e2e52650-39ab-11e9-ad8d-000c29342cb1 // CNVD: CNVD-2018-04834 // BID: 103379 // JVNDB: JVNDB-2018-002719 // CNNVD: CNNVD-201803-230 // NVD: CVE-2018-4838

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-4838
value: HIGH

Trust: 1.0

NVD: CVE-2018-4838
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-04834
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201803-230
value: HIGH

Trust: 0.6

IVD: e2e52650-39ab-11e9-ad8d-000c29342cb1
value: HIGH

Trust: 0.2

VULHUB: VHN-134869
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-4838
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-04834
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:C/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: e2e52650-39ab-11e9-ad8d-000c29342cb1
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:C/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-134869
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-4838
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: IVD: e2e52650-39ab-11e9-ad8d-000c29342cb1 // CNVD: CNVD-2018-04834 // VULHUB: VHN-134869 // JVNDB: JVNDB-2018-002719 // CNNVD: CNNVD-201803-230 // NVD: CVE-2018-4838

PROBLEMTYPE DATA

problemtype:CWE-306

Trust: 1.1

problemtype:CWE-284

Trust: 0.9

sources: VULHUB: VHN-134869 // JVNDB: JVNDB-2018-002719 // NVD: CVE-2018-4838

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201803-230

TYPE

Access control error

Trust: 0.8

sources: IVD: e2e52650-39ab-11e9-ad8d-000c29342cb1 // CNNVD: CNNVD-201803-230

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-002719

PATCH

title:SSA-845879url:https://cert-portal.siemens.com/productcert/pdf/ssa-845879.pdf

Trust: 0.8

title:Patches for unauthorized operating vulnerabilities in multiple Siemens productsurl:https://www.cnvd.org.cn/patchInfo/show/120859

Trust: 0.6

title:Multiple Siemens Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=78966

Trust: 0.6

sources: CNVD: CNVD-2018-04834 // JVNDB: JVNDB-2018-002719 // CNNVD: CNNVD-201803-230

EXTERNAL IDS

db:NVDid:CVE-2018-4838

Trust: 3.6

db:BIDid:103379

Trust: 2.0

db:SIEMENSid:SSA-845879

Trust: 2.0

db:ICS CERTid:ICSA-18-067-02

Trust: 1.7

db:ICS CERTid:ICSA-18-067-01

Trust: 1.6

db:CNNVDid:CNNVD-201803-230

Trust: 0.9

db:CNVDid:CNVD-2018-04834

Trust: 0.8

db:JVNDBid:JVNDB-2018-002719

Trust: 0.8

db:IVDid:E2E52650-39AB-11E9-AD8D-000C29342CB1

Trust: 0.2

db:VULHUBid:VHN-134869

Trust: 0.1

sources: IVD: e2e52650-39ab-11e9-ad8d-000c29342cb1 // CNVD: CNVD-2018-04834 // VULHUB: VHN-134869 // BID: 103379 // JVNDB: JVNDB-2018-002719 // CNNVD: CNNVD-201803-230 // NVD: CVE-2018-4838

REFERENCES

url:https://cert-portal.siemens.com/productcert/pdf/ssa-845879.pdf

Trust: 2.0

url:https://ics-cert.us-cert.gov/advisories/icsa-18-067-02

Trust: 1.7

url:https://www.securityfocus.com/bid/103379

Trust: 1.7

url:https://ics-cert.us-cert.gov/advisories/icsa-18-067-01

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-4838

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-4838

Trust: 0.8

url:http://www.siemens.com/

Trust: 0.3

sources: CNVD: CNVD-2018-04834 // VULHUB: VHN-134869 // BID: 103379 // JVNDB: JVNDB-2018-002719 // CNNVD: CNNVD-201803-230 // NVD: CVE-2018-4838

CREDITS

Ilya Karpov and Alexey Stennikov from Positive Technologies

Trust: 0.3

sources: BID: 103379

SOURCES

db:IVDid:e2e52650-39ab-11e9-ad8d-000c29342cb1
db:CNVDid:CNVD-2018-04834
db:VULHUBid:VHN-134869
db:BIDid:103379
db:JVNDBid:JVNDB-2018-002719
db:CNNVDid:CNNVD-201803-230
db:NVDid:CVE-2018-4838

LAST UPDATE DATE

2024-11-23T22:45:24.584000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-04834date:2018-03-09T00:00:00
db:VULHUBid:VHN-134869date:2019-10-03T00:00:00
db:BIDid:103379date:2018-03-08T00:00:00
db:JVNDBid:JVNDB-2018-002719date:2018-04-26T00:00:00
db:CNNVDid:CNNVD-201803-230date:2019-10-08T00:00:00
db:NVDid:CVE-2018-4838date:2024-11-21T04:07:33.400

SOURCES RELEASE DATE

db:IVDid:e2e52650-39ab-11e9-ad8d-000c29342cb1date:2018-03-09T00:00:00
db:CNVDid:CNVD-2018-04834date:2018-03-09T00:00:00
db:VULHUBid:VHN-134869date:2018-03-08T00:00:00
db:BIDid:103379date:2018-03-08T00:00:00
db:JVNDBid:JVNDB-2018-002719date:2018-04-26T00:00:00
db:CNNVDid:CNNVD-201803-230date:2018-03-09T00:00:00
db:NVDid:CVE-2018-4838date:2018-03-08T17:29:00.210