ID

VAR-201812-0343


CVE

CVE-2018-13812


TITLE

plural SIMATIC Path traversal vulnerability in products

Trust: 0.8

sources: JVNDB: JVNDB-2018-014525

DESCRIPTION

A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15 Update 4), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15 Update 4), SIMATIC WinCC Runtime Advanced (All versions < V15 Update 4), SIMATIC WinCC Runtime Professional (All versions < V15 Update 4), SIMATIC WinCC (TIA Portal) (All versions < V15 Update 4), SIMATIC HMI Classic Devices (TP/MP/OP/MP Mobile Panel) (All versions). A directory traversal vulnerability could allow to download arbitrary files from the device. The security vulnerability could be exploited by an attacker with network access to the integrated web server. No user interaction and no authentication is required to exploit the vulnerability. The vulnerability impacts the confidentiality of the device. At the time of advisory publication no public exploitation of this security vulnerability was known. plural SIMATIC The product contains a path traversal vulnerability.Information may be obtained. Siemens SIMATIC Panels is prone to following security vulnerabilities: 1. An open-redirection vulnerability 2. A directory-traversal vulnerability Remote attackers may use a specially crafted request with directory-traversal sequences ('../') to retrieve arbitrary files from the affected system in the context of the application or by constructing a crafted URI and enticing a user to follow it and when an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site. are all HMI software used by Siemens in Germany to control and monitor machines and equipment

Trust: 1.98

sources: NVD: CVE-2018-13812 // JVNDB: JVNDB-2018-014525 // BID: 105922 // VULHUB: VHN-123909

AFFECTED PRODUCTS

vendor:siemensmodel:simatic wincc \scope:lteversion:15.0

Trust: 1.0

vendor:siemensmodel:simatic hmi ktp mobile panels ktp900scope:lteversion:15.0

Trust: 1.0

vendor:siemensmodel:simatic hmi comfort panelsscope:lteversion:15.0

Trust: 1.0

vendor:siemensmodel:simatic hmi comfort outdoor panelsscope:lteversion:15.0

Trust: 1.0

vendor:siemensmodel:simatic hmi mpscope:eqversion:*

Trust: 1.0

vendor:siemensmodel:simatic wincc runtimescope:lteversion:15.0

Trust: 1.0

vendor:siemensmodel:simatic hmi ktp mobile panels ktp400fscope:lteversion:15.0

Trust: 1.0

vendor:siemensmodel:simatic hmi ktp mobile panels ktp900fscope:lteversion:15.0

Trust: 1.0

vendor:siemensmodel:simatic hmi ktp mobile panels ktp700fscope:lteversion:15.0

Trust: 1.0

vendor:siemensmodel:simatic hmi opscope:eqversion:*

Trust: 1.0

vendor:siemensmodel:simatic hmi tpscope:eqversion:*

Trust: 1.0

vendor:siemensmodel:simatic hmi ktp mobile panels ktp700scope:lteversion:15.0

Trust: 1.0

vendor:siemensmodel:simatic hmi comfort outdoor panelsscope: - version: -

Trust: 0.8

vendor:siemensmodel:simatic hmi comfort panelsscope: - version: -

Trust: 0.8

vendor:siemensmodel:simatic hmi ktp mobile panels ktp400fscope: - version: -

Trust: 0.8

vendor:siemensmodel:simatic hmi ktp mobile panels ktp700scope: - version: -

Trust: 0.8

vendor:siemensmodel:simatic hmi ktp mobile panels ktp700fscope: - version: -

Trust: 0.8

vendor:siemensmodel:simatic hmi ktp mobile panels ktp900scope: - version: -

Trust: 0.8

vendor:siemensmodel:simatic hmi ktp mobile panels ktp900fscope: - version: -

Trust: 0.8

vendor:siemensmodel:simatic winccscope: - version: -

Trust: 0.8

vendor:siemensmodel:simatic wincc runtime advancedscope: - version: -

Trust: 0.8

vendor:siemensmodel:simatic wincc runtime professionalscope: - version: -

Trust: 0.8

vendor:siemensmodel:simatic wincc runtime professionalscope:eqversion:15

Trust: 0.3

vendor:siemensmodel:simatic wincc runtime professional sp1scope:eqversion:14

Trust: 0.3

vendor:siemensmodel:simatic wincc runtime professionalscope:eqversion:14

Trust: 0.3

vendor:siemensmodel:simatic wincc runtime professional sp2scope:eqversion:13

Trust: 0.3

vendor:siemensmodel:simatic wincc runtime professional sp1 upd2scope:eqversion:13

Trust: 0.3

vendor:siemensmodel:simatic wincc runtime professional sp updatescope:eqversion:1319

Trust: 0.3

vendor:siemensmodel:simatic wincc runtime professionalscope:eqversion:13

Trust: 0.3

vendor:siemensmodel:simatic wincc runtime advancedscope:eqversion:15

Trust: 0.3

vendor:siemensmodel:simatic wincc runtime advanced sp1 upd2scope:eqversion:13

Trust: 0.3

vendor:siemensmodel:simatic wincc runtime advancedscope:eqversion:13

Trust: 0.3

vendor:siemensmodel:simatic wincc runtime advanced sp1 upd5scope:eqversion:12

Trust: 0.3

vendor:siemensmodel:simatic wincc runtime advancedscope:eqversion:12

Trust: 0.3

vendor:siemensmodel:simatic wincc runtime advancedscope:eqversion:0

Trust: 0.3

vendor:siemensmodel:simatic wincc updatescope:eqversion:v135

Trust: 0.3

vendor:siemensmodel:simatic wincc sp1scope:eqversion:v12

Trust: 0.3

vendor:siemensmodel:simatic winccscope:eqversion:v120

Trust: 0.3

vendor:siemensmodel:simatic winccscope:eqversion:v110

Trust: 0.3

vendor:siemensmodel:simatic winccscope:eqversion:v15

Trust: 0.3

vendor:siemensmodel:simatic wincc updatescope:eqversion:v136

Trust: 0.3

vendor:siemensmodel:simatic wincc sp1scope:eqversion:v13

Trust: 0.3

vendor:siemensmodel:simatic winccscope:eqversion:v13

Trust: 0.3

vendor:siemensmodel:simatic winccscope:eqversion:v10

Trust: 0.3

vendor:siemensmodel:simatic hmi ktp mobile panelsscope:eqversion:0

Trust: 0.3

vendor:siemensmodel:simatic hmi comfort panelsscope:eqversion:4

Trust: 0.3

vendor:siemensmodel:simatic hmi comfort panelsscope:eqversion:22

Trust: 0.3

vendor:siemensmodel:simatic hmi comfort panelsscope:eqversion:15

Trust: 0.3

vendor:siemensmodel:simatic hmi comfort panels sp1 upd2scope:eqversion:13

Trust: 0.3

vendor:siemensmodel:simatic hmi comfort panelsscope:eqversion:13

Trust: 0.3

vendor:siemensmodel:simatic hmi comfort panels sp1 upd5scope:eqversion:12

Trust: 0.3

vendor:siemensmodel:simatic hmi comfort panelsscope:eqversion:12

Trust: 0.3

vendor:siemensmodel:simatic hmi comfort panelsscope:eqversion:0

Trust: 0.3

vendor:siemensmodel:simatic hmi comfort outdoor panelsscope:eqversion:0

Trust: 0.3

vendor:siemensmodel:simatic hmi classic devicesscope:eqversion:0

Trust: 0.3

vendor:siemensmodel:simatic wincc runtime professional updatescope:neversion:154

Trust: 0.3

vendor:siemensmodel:simatic wincc runtime advanced updatescope:neversion:154

Trust: 0.3

vendor:siemensmodel:simatic wincc updatescope:neversion:154

Trust: 0.3

vendor:siemensmodel:simatic hmi ktp mobile panels updatescope:neversion:154

Trust: 0.3

vendor:siemensmodel:simatic hmi comfort panels updatescope:neversion:154

Trust: 0.3

vendor:siemensmodel:simatic hmi comfort outdoor panels updatescope:neversion:154

Trust: 0.3

sources: BID: 105922 // JVNDB: JVNDB-2018-014525 // NVD: CVE-2018-13812

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-13812
value: HIGH

Trust: 1.0

NVD: CVE-2018-13812
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201811-482
value: HIGH

Trust: 0.6

VULHUB: VHN-123909
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-13812
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-123909
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-13812
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-123909 // JVNDB: JVNDB-2018-014525 // CNNVD: CNNVD-201811-482 // NVD: CVE-2018-13812

PROBLEMTYPE DATA

problemtype:CWE-22

Trust: 1.9

sources: VULHUB: VHN-123909 // JVNDB: JVNDB-2018-014525 // NVD: CVE-2018-13812

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201811-482

TYPE

path traversal

Trust: 0.6

sources: CNNVD: CNNVD-201811-482

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-014525

PATCH

title:SSA-233109url:https://cert-portal.siemens.com/productcert/pdf/ssa-233109.pdf

Trust: 0.8

title:Multiple Siemens Product path traversal vulnerability fixesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=86883

Trust: 0.6

sources: JVNDB: JVNDB-2018-014525 // CNNVD: CNNVD-201811-482

EXTERNAL IDS

db:NVDid:CVE-2018-13812

Trust: 2.8

db:BIDid:105922

Trust: 2.0

db:SIEMENSid:SSA-233109

Trust: 1.7

db:ICS CERTid:ICSA-18-317-08

Trust: 1.7

db:JVNDBid:JVNDB-2018-014525

Trust: 0.8

db:CNNVDid:CNNVD-201811-482

Trust: 0.7

db:VULHUBid:VHN-123909

Trust: 0.1

sources: VULHUB: VHN-123909 // BID: 105922 // JVNDB: JVNDB-2018-014525 // CNNVD: CNNVD-201811-482 // NVD: CVE-2018-13812

REFERENCES

url:http://www.securityfocus.com/bid/105922

Trust: 1.7

url:https://cert-portal.siemens.com/productcert/pdf/ssa-233109.pdf

Trust: 1.7

url:https://ics-cert.us-cert.gov/advisories/icsa-18-317-08

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-13812

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-13812

Trust: 0.8

url:http://subscriber.communications.siemens.com/

Trust: 0.3

sources: VULHUB: VHN-123909 // BID: 105922 // JVNDB: JVNDB-2018-014525 // CNNVD: CNNVD-201811-482 // NVD: CVE-2018-13812

CREDITS

Hosni Tounsi from Carthage Red Team

Trust: 0.3

sources: BID: 105922

SOURCES

db:VULHUBid:VHN-123909
db:BIDid:105922
db:JVNDBid:JVNDB-2018-014525
db:CNNVDid:CNNVD-201811-482
db:NVDid:CVE-2018-13812

LAST UPDATE DATE

2024-08-14T15:12:58.695000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-123909date:2019-10-09T00:00:00
db:BIDid:105922date:2018-11-14T00:00:00
db:JVNDBid:JVNDB-2018-014525date:2019-03-26T00:00:00
db:CNNVDid:CNNVD-201811-482date:2019-10-17T00:00:00
db:NVDid:CVE-2018-13812date:2019-10-09T23:34:33.327

SOURCES RELEASE DATE

db:VULHUBid:VHN-123909date:2018-12-13T00:00:00
db:BIDid:105922date:2018-11-14T00:00:00
db:JVNDBid:JVNDB-2018-014525date:2019-03-26T00:00:00
db:CNNVDid:CNNVD-201811-482date:2018-11-15T00:00:00
db:NVDid:CVE-2018-13812date:2018-12-13T16:29:00.290