ID

VAR-201803-2156


CVE

CVE-2018-4839


TITLE

plural Siemens Authorization vulnerabilities in products

Trust: 0.8

sources: JVNDB: JVNDB-2018-002720

DESCRIPTION

A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions), Other SIPROTEC 4 relays (All versions), Other SIPROTEC Compact relays (All versions), SIPROTEC 4 7SD80 (All versions < V4.70), SIPROTEC 4 7SJ61 (All versions < V4.96), SIPROTEC 4 7SJ62 (All versions < V4.96), SIPROTEC 4 7SJ64 (All versions < V4.96), SIPROTEC 4 7SJ66 (All versions < V4.30), SIPROTEC Compact 7SJ80 (All versions < V4.77), SIPROTEC Compact 7SK80 (All versions < V4.77). An attacker with local access to the engineering system or in a privileged network position and able to obtain certain network traffic could possibly reconstruct access authorization passwords. plural Siemens The product contains an authorization vulnerability.Information may be obtained. Siemens DIGSI and others are products of Siemens AG. The Siemens DIGSI is a configuration operating software for the microcomputer protection. EN100 Ethernet module The IEC 61850 variant is an Ethernet module product. Security vulnerabilities exist in several Siemens products. An attacker could exploit the vulnerability to re-establish an access authorization password

Trust: 2.7

sources: NVD: CVE-2018-4839 // JVNDB: JVNDB-2018-002720 // CNVD: CNVD-2018-05196 // BID: 107481 // IVD: e2e5e9a1-39ab-11e9-9407-000c29342cb1 // VULHUB: VHN-134870

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: e2e5e9a1-39ab-11e9-9407-000c29342cb1 // CNVD: CNVD-2018-05196

AFFECTED PRODUCTS

vendor:siemensmodel:siprotec compact 7sk80scope:ltversion:4.77

Trust: 1.8

vendor:siemensmodel:siprotec compact 7sj80scope:ltversion:4.77

Trust: 1.8

vendor:siemensmodel:en100 ethernet module dnp3scope:eqversion: -

Trust: 1.6

vendor:siemensmodel:en100 ethernet module modbus tcpscope:eqversion: -

Trust: 1.6

vendor:siemensmodel:en100 ethernet module profinet ioscope:eqversion: -

Trust: 1.6

vendor:siemensmodel:en100 ethernet module iec 104scope:eqversion: -

Trust: 1.6

vendor:siemensmodel:siprotec compact 7sk80scope: - version: -

Trust: 1.1

vendor:siemensmodel:siprotec compact 7sj80scope: - version: -

Trust: 1.1

vendor:siemensmodel:digsi 4scope:ltversion:4.92

Trust: 1.0

vendor:siemensmodel:en100 ethernet module iec 61850scope:ltversion:4.30

Trust: 1.0

vendor:siemensmodel:siprotec 4 7sj66scope:ltversion:4.30

Trust: 1.0

vendor:siemensmodel:digsiscope:ltversion:44.92

Trust: 0.8

vendor:siemensmodel:en100 ethernet module iec variantscope:eqversion:61850<4.30

Trust: 0.8

vendor:siemensmodel:siprotec compact 7sj66scope:ltversion:4.30

Trust: 0.8

vendor:siemensmodel:digsi 4scope: - version: -

Trust: 0.8

vendor:siemensmodel:en100 ethernet module dnp3scope: - version: -

Trust: 0.8

vendor:siemensmodel:en100 ethernet module iec 104scope: - version: -

Trust: 0.8

vendor:siemensmodel:en100 ethernet module iec 61850scope: - version: -

Trust: 0.8

vendor:siemensmodel:en100 ethernet module modbus tcpscope: - version: -

Trust: 0.8

vendor:siemensmodel:en100 ethernet module profinet ioscope: - version: -

Trust: 0.8

vendor:siemensmodel:siprotec 4 7sj66scope: - version: -

Trust: 0.8

vendor:siemensmodel:en100 ethernet module profinet io variantscope: - version: -

Trust: 0.6

vendor:siemensmodel:en100 ethernet module modbus tcp variantscope: - version: -

Trust: 0.6

vendor:siemensmodel:en100 ethernet module dnp3 variantscope: - version: -

Trust: 0.6

vendor:siemensmodel:en100 ethernet module iec variantscope:eqversion:104

Trust: 0.6

vendor:siemensmodel:siprotec compactscope:eqversion:0

Trust: 0.3

vendor:siemensmodel:siprotec 7sj66scope:eqversion:4

Trust: 0.3

vendor:siemensmodel:siprotec 7sj64scope:eqversion:4

Trust: 0.3

vendor:siemensmodel:siprotec 7sj62scope:eqversion:4

Trust: 0.3

vendor:siemensmodel:siprotec 7sj61scope:eqversion:4

Trust: 0.3

vendor:siemensmodel:siprotec 7sd80scope:eqversion:4

Trust: 0.3

vendor:siemensmodel:siprotecscope:eqversion:40

Trust: 0.3

vendor:siemensmodel:en100 ethernet module profinet ioscope:eqversion:0

Trust: 0.3

vendor:siemensmodel:en100 ethernet module modbus tcpscope:eqversion:0

Trust: 0.3

vendor:siemensmodel:en100 ethernet module iecscope:eqversion:618500

Trust: 0.3

vendor:siemensmodel:en100 ethernet module iecscope:eqversion:1040

Trust: 0.3

vendor:siemensmodel:en100 ethernet module dnp3scope:eqversion:0

Trust: 0.3

vendor:siemensmodel:digsiscope:eqversion:40

Trust: 0.3

vendor:siemensmodel:siprotec compact 7sk80scope:neversion:4.77

Trust: 0.3

vendor:siemensmodel:siprotec compact 7sj80scope:neversion:4.77

Trust: 0.3

vendor:siemensmodel:siprotec 7sj66scope:neversion:44.30

Trust: 0.3

vendor:siemensmodel:siprotec 7sj64scope:neversion:44.96

Trust: 0.3

vendor:siemensmodel:siprotec 7sj61scope:neversion:44.96

Trust: 0.3

vendor:siemensmodel:siprotec 7sd80scope:neversion:44.70

Trust: 0.3

vendor:siemensmodel:en100 ethernet module iecscope:neversion:618504.30

Trust: 0.3

vendor:siemensmodel:en100 ethernet module dnp3scope:neversion:4.30

Trust: 0.3

vendor:siemensmodel:digsiscope:neversion:44.92

Trust: 0.3

vendor:siemensmodel:en100 ethernet module profinet io variantscope:eqversion:*

Trust: 0.2

vendor:siemensmodel:en100 ethernet module modbus tcp variantscope:eqversion:*

Trust: 0.2

vendor:siemensmodel:en100 ethernet module dnp3 variantscope:eqversion:*

Trust: 0.2

vendor:siemensmodel:en100 ethernet module iec variantscope:eqversion:104*

Trust: 0.2

sources: IVD: e2e5e9a1-39ab-11e9-9407-000c29342cb1 // CNVD: CNVD-2018-05196 // BID: 107481 // JVNDB: JVNDB-2018-002720 // CNNVD: CNNVD-201803-229 // NVD: CVE-2018-4839

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-4839
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-4839
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2018-05196
value: LOW

Trust: 0.6

CNNVD: CNNVD-201803-229
value: MEDIUM

Trust: 0.6

IVD: e2e5e9a1-39ab-11e9-9407-000c29342cb1
value: MEDIUM

Trust: 0.2

VULHUB: VHN-134870
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2018-4839
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-05196
severity: LOW
baseScore: 2.6
vectorString: AV:N/AC:H/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 4.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: e2e5e9a1-39ab-11e9-9407-000c29342cb1
severity: LOW
baseScore: 2.6
vectorString: AV:N/AC:H/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 4.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-134870
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-4839
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.6
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: IVD: e2e5e9a1-39ab-11e9-9407-000c29342cb1 // CNVD: CNVD-2018-05196 // VULHUB: VHN-134870 // JVNDB: JVNDB-2018-002720 // CNNVD: CNNVD-201803-229 // NVD: CVE-2018-4839

PROBLEMTYPE DATA

problemtype:CWE-326

Trust: 1.1

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-285

Trust: 0.9

sources: VULHUB: VHN-134870 // JVNDB: JVNDB-2018-002720 // NVD: CVE-2018-4839

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201803-229

TYPE

encryption problem

Trust: 0.6

sources: CNNVD: CNNVD-201803-229

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-002720

PATCH

title:SSA-203306url:https://cert-portal.siemens.com/productcert/pdf/ssa-203306.pdf

Trust: 0.8

title:Patches for unidentified vulnerabilities in various Siemens productsurl:https://www.cnvd.org.cn/patchInfo/show/121391

Trust: 0.6

title:Multiple Siemens Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=78965

Trust: 0.6

sources: CNVD: CNVD-2018-05196 // JVNDB: JVNDB-2018-002720 // CNNVD: CNNVD-201803-229

EXTERNAL IDS

db:NVDid:CVE-2018-4839

Trust: 3.6

db:ICS CERTid:ICSA-18-067-01

Trust: 3.0

db:SIEMENSid:SSA-203306

Trust: 2.0

db:CNVDid:CNVD-2018-05196

Trust: 0.8

db:CNNVDid:CNNVD-201803-229

Trust: 0.8

db:JVNDBid:JVNDB-2018-002720

Trust: 0.8

db:BIDid:107481

Trust: 0.3

db:IVDid:E2E5E9A1-39AB-11E9-9407-000C29342CB1

Trust: 0.2

db:VULHUBid:VHN-134870

Trust: 0.1

sources: IVD: e2e5e9a1-39ab-11e9-9407-000c29342cb1 // CNVD: CNVD-2018-05196 // VULHUB: VHN-134870 // BID: 107481 // JVNDB: JVNDB-2018-002720 // CNNVD: CNNVD-201803-229 // NVD: CVE-2018-4839

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-18-067-01

Trust: 3.0

url:https://cert-portal.siemens.com/productcert/pdf/ssa-203306.pdf

Trust: 2.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-4839

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-4839

Trust: 0.8

url:http://w3.siemens.com/smartgrid/global/en/products-systems-solutions/protection/siprotec4/pages/overview.aspx

Trust: 0.3

url:http://w3.siemens.com/smartgrid/global/en/products-systems-solutions/protection/siprotec-compact/pages/overview.aspx

Trust: 0.3

url:http://subscriber.communications.siemens.com/

Trust: 0.3

sources: CNVD: CNVD-2018-05196 // VULHUB: VHN-134870 // BID: 107481 // JVNDB: JVNDB-2018-002720 // CNNVD: CNNVD-201803-229 // NVD: CVE-2018-4839

CREDITS

Ilya Karpov and Dmitry Sklyarov from Positive Technologies.

Trust: 0.3

sources: BID: 107481

SOURCES

db:IVDid:e2e5e9a1-39ab-11e9-9407-000c29342cb1
db:CNVDid:CNVD-2018-05196
db:VULHUBid:VHN-134870
db:BIDid:107481
db:JVNDBid:JVNDB-2018-002720
db:CNNVDid:CNNVD-201803-229
db:NVDid:CVE-2018-4839

LAST UPDATE DATE

2024-11-23T22:45:24.544000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-05196date:2018-03-14T00:00:00
db:VULHUBid:VHN-134870date:2021-07-13T00:00:00
db:BIDid:107481date:2018-03-08T00:00:00
db:JVNDBid:JVNDB-2018-002720date:2018-04-26T00:00:00
db:CNNVDid:CNNVD-201803-229date:2021-07-14T00:00:00
db:NVDid:CVE-2018-4839date:2024-11-21T04:07:33.527

SOURCES RELEASE DATE

db:IVDid:e2e5e9a1-39ab-11e9-9407-000c29342cb1date:2018-03-14T00:00:00
db:CNVDid:CNVD-2018-05196date:2018-03-13T00:00:00
db:VULHUBid:VHN-134870date:2018-03-08T00:00:00
db:BIDid:107481date:2018-03-08T00:00:00
db:JVNDBid:JVNDB-2018-002720date:2018-04-26T00:00:00
db:CNNVDid:CNNVD-201803-229date:2018-03-09T00:00:00
db:NVDid:CVE-2018-4839date:2018-03-08T17:29:00.257