Network Scanning Vulnerability in Automation License Manager by Siemens
CVE-2018-11456
5.8MEDIUM
What is CVE-2018-11456?
A network vulnerability has been discovered in Automation License Manager 5, specifically affecting all versions below 5.3.4.4. This vulnerability allows an attacker with network access to the affected device to send specially crafted network packets. This can enable the attacker to determine the accessibility of network ports on remote systems, facilitating a form of basic network scanning through the compromised device. Notably, successful exploitation does not require any user privileges or interaction, thereby posing a risk to the security stance of networks utilizing this software.
Affected Version(s)
Automation License Manager 5 Automation License Manager 5 : All versions < 5.3.4.4