ID

VAR-201812-0459


CVE

CVE-2018-11464


TITLE

SINUMERIK 828D and SINUMERIK 840D sl Vulnerabilities related to authorization, permissions, and access control

Trust: 0.8

sources: JVNDB: JVNDB-2018-013112

DESCRIPTION

A vulnerability has been identified in SINUMERIK 828D V4.7 (All versions < V4.7 SP6 HF1), SINUMERIK 840D sl V4.7 (All versions < V4.7 SP6 HF5), SINUMERIK 840D sl V4.8 (All versions < V4.8 SP3). The integrated VNC server on port 5900/tcp of the affected products could allow a remote attacker to cause a Denial-of-Service condition of the VNC server. Please note that this vulnerability is only exploitable if port 5900/tcp is manually opened in the firewall configuration of network port X130. The security vulnerability could be exploited by an attacker with network access to the affected devices and port. Successful exploitation requires no privileges and no user interaction. The vulnerability could allow an attacker to compromise availability of the VNC server. At the time of advisory publication no public exploitation of this security vulnerability was known. SINUMERIK 828D and SINUMERIK 840D sl Contains vulnerabilities related to authorization, permissions, and access control.Service operation interruption (DoS) There is a possibility of being put into a state. The Siemens SINUMERIK 808D is a CNC machine system controller from Siemens AG. Security vulnerabilities exist in several Siemens products. A heap based buffer-overflow vulnerability. 2. An integer overflow vulnerability. 3. A security bypass vulnerability. 4. An arbitrary code execution vulnerability. 5. Multiple privilege escalation vulnerabilities. 6. A stack based buffer-overflow vulnerability. 7. A buffer-overflow vulnerability. 8. Multiple denial-of-service vulnerabilities Attackers can exploit these issues to execute arbitrary code within the context of affected device, gain host privileges and perform unauthorized actions, to modify or destroy data without having proper authorization to do so, to bypass security restrictions or cause a denial-of-service condition. Siemens SINUMERIK 808D, etc

Trust: 2.7

sources: NVD: CVE-2018-11464 // JVNDB: JVNDB-2018-013112 // CNVD: CNVD-2018-25421 // BID: 106185 // IVD: 7d8171b0-463f-11e9-8d83-000c29342cb1 // VULHUB: VHN-121326

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 7d8171b0-463f-11e9-8d83-000c29342cb1 // CNVD: CNVD-2018-25421

AFFECTED PRODUCTS

vendor:siemensmodel:sinumerik 840d slscope:lteversion:4.7

Trust: 1.0

vendor:siemensmodel:sinumerik 828dscope:lteversion:4.7

Trust: 1.0

vendor:siemensmodel:sinumerik 840d slscope:lteversion:4.8

Trust: 1.0

vendor:siemensmodel:sinumerik 840d slscope:eqversion:4.8

Trust: 0.9

vendor:siemensmodel:sinumerik 840d slscope:eqversion:4.7

Trust: 0.9

vendor:siemensmodel:sinumerik 828dscope:eqversion:4.7

Trust: 0.9

vendor:siemensmodel:sinumerik 828dscope: - version: -

Trust: 0.8

vendor:siemensmodel:sinumerik 840d slscope: - version: -

Trust: 0.8

vendor:siemensmodel:sinumerik 808dscope:eqversion:v4.7

Trust: 0.6

vendor:siemensmodel:sinumerik 808dscope:eqversion:v4.8

Trust: 0.6

vendor:siemensmodel:sinumerik 840d sp6 hf5scope:ltversion:v4.7

Trust: 0.6

vendor:siemensmodel:sinumerik 840d sp3scope:ltversion:v4.8

Trust: 0.6

vendor:siemensmodel:sinumerik 828d sp6 hf1scope:ltversion:v4.7

Trust: 0.6

vendor:sinumerik 840d slmodel: - scope:eqversion:*

Trust: 0.4

vendor:siemensmodel:sinumerik 808dscope:eqversion:4.8

Trust: 0.3

vendor:siemensmodel:sinumerik 808dscope:eqversion:4.7

Trust: 0.3

vendor:siemensmodel:sinumerik 840d sl sp3scope:neversion:4.8

Trust: 0.3

vendor:siemensmodel:sinumerik 840d sl sp6 hf5scope:neversion:4.7

Trust: 0.3

vendor:siemensmodel:sinumerik 828d sp6 hf1scope:neversion:4.7

Trust: 0.3

vendor:sinumerik 828dmodel: - scope:eqversion:*

Trust: 0.2

sources: IVD: 7d8171b0-463f-11e9-8d83-000c29342cb1 // CNVD: CNVD-2018-25421 // BID: 106185 // JVNDB: JVNDB-2018-013112 // CNNVD: CNNVD-201812-605 // NVD: CVE-2018-11464

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-11464
value: LOW

Trust: 1.0

NVD: CVE-2018-11464
value: LOW

Trust: 0.8

CNVD: CNVD-2018-25421
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201812-605
value: LOW

Trust: 0.6

IVD: 7d8171b0-463f-11e9-8d83-000c29342cb1
value: LOW

Trust: 0.2

VULHUB: VHN-121326
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-11464
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-25421
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 7d8171b0-463f-11e9-8d83-000c29342cb1
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-121326
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-11464
baseSeverity: LOW
baseScore: 3.7
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: LOW
exploitabilityScore: 2.2
impactScore: 1.4
version: 3.0

Trust: 1.8

sources: IVD: 7d8171b0-463f-11e9-8d83-000c29342cb1 // CNVD: CNVD-2018-25421 // VULHUB: VHN-121326 // JVNDB: JVNDB-2018-013112 // CNNVD: CNNVD-201812-605 // NVD: CVE-2018-11464

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-248

Trust: 1.0

problemtype:CWE-264

Trust: 0.8

sources: JVNDB: JVNDB-2018-013112 // NVD: CVE-2018-11464

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201812-605

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201812-605

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-013112

PATCH

title:SSA-170881url:https://cert-portal.siemens.com/productcert/pdf/ssa-170881.pdf

Trust: 0.8

title:Patches for multiple Siemens product denial of service vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/147349

Trust: 0.6

title:Multiple Siemens Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=87849

Trust: 0.6

sources: CNVD: CNVD-2018-25421 // JVNDB: JVNDB-2018-013112 // CNNVD: CNNVD-201812-605

EXTERNAL IDS

db:NVDid:CVE-2018-11464

Trust: 3.6

db:SIEMENSid:SSA-170881

Trust: 2.6

db:BIDid:106185

Trust: 2.0

db:ICS CERTid:ICSA-18-345-02

Trust: 1.1

db:CNNVDid:CNNVD-201812-605

Trust: 0.9

db:CNVDid:CNVD-2018-25421

Trust: 0.8

db:JVNDBid:JVNDB-2018-013112

Trust: 0.8

db:IVDid:7D8171B0-463F-11E9-8D83-000C29342CB1

Trust: 0.2

db:VULHUBid:VHN-121326

Trust: 0.1

sources: IVD: 7d8171b0-463f-11e9-8d83-000c29342cb1 // CNVD: CNVD-2018-25421 // VULHUB: VHN-121326 // BID: 106185 // JVNDB: JVNDB-2018-013112 // CNNVD: CNNVD-201812-605 // NVD: CVE-2018-11464

REFERENCES

url:https://cert-portal.siemens.com/productcert/pdf/ssa-170881.pdf

Trust: 2.6

url:http://www.securityfocus.com/bid/106185

Trust: 1.7

url:https://ics-cert.us-cert.gov/advisories/icsa-18-345-02

Trust: 1.1

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-11464

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-11464

Trust: 0.8

url:http://subscriber.communications.siemens.com/

Trust: 0.3

url:https://www.industry.siemens.com/topics/global/en/cnc4you/cnc_downloads/sinutrain_downloads/pages/sinutrain_downloads.aspx

Trust: 0.3

sources: CNVD: CNVD-2018-25421 // VULHUB: VHN-121326 // BID: 106185 // JVNDB: JVNDB-2018-013112 // CNNVD: CNNVD-201812-605 // NVD: CVE-2018-11464

CREDITS

Anton Kalinin, Danila Parnishchev, Dmitry Sklyar, Gleb Gritsai, Kirill Nesterov, Radu Motspan, and Sergey Sidorov from Kaspersky Lab.

Trust: 0.3

sources: BID: 106185

SOURCES

db:IVDid:7d8171b0-463f-11e9-8d83-000c29342cb1
db:CNVDid:CNVD-2018-25421
db:VULHUBid:VHN-121326
db:BIDid:106185
db:JVNDBid:JVNDB-2018-013112
db:CNNVDid:CNNVD-201812-605
db:NVDid:CVE-2018-11464

LAST UPDATE DATE

2024-08-14T13:45:24.069000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-25421date:2018-12-14T00:00:00
db:VULHUBid:VHN-121326date:2019-10-09T00:00:00
db:BIDid:106185date:2018-12-11T00:00:00
db:JVNDBid:JVNDB-2018-013112date:2019-03-14T00:00:00
db:CNNVDid:CNNVD-201812-605date:2019-10-17T00:00:00
db:NVDid:CVE-2018-11464date:2019-10-09T23:33:33.947

SOURCES RELEASE DATE

db:IVDid:7d8171b0-463f-11e9-8d83-000c29342cb1date:2018-12-14T00:00:00
db:CNVDid:CNVD-2018-25421date:2018-12-14T00:00:00
db:VULHUBid:VHN-121326date:2018-12-12T00:00:00
db:BIDid:106185date:2018-12-11T00:00:00
db:JVNDBid:JVNDB-2018-013112date:2019-02-14T00:00:00
db:CNNVDid:CNNVD-201812-605date:2018-12-12T00:00:00
db:NVDid:CVE-2018-11464date:2018-12-12T16:29:00.590