Local Code Execution Vulnerability in SINUMERIK Systems by Siemens
CVE-2018-11459
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 12 December 2018
Summary
A local code execution vulnerability exists in various SINUMERIK systems from Siemens that allows an attacker with local access to modify a user-writable configuration file. Upon system reboot or manual initiation, the modified configuration file executes attacker-controlled code with elevated privileges. This exploitation could lead to risks concerning the confidentiality, integrity, and availability of the system. At the time of the advisory release, there was no public evidence of successful exploitation.
Affected Version(s)
SINUMERIK 808D V4.7, SINUMERIK 808D V4.8, SINUMERIK 828D V4.7, SINUMERIK 840D sl V4.7, SINUMERIK 840D sl V4.8 SINUMERIK 808D V4.7 : All versions
SINUMERIK 808D V4.7, SINUMERIK 808D V4.8, SINUMERIK 828D V4.7, SINUMERIK 840D sl V4.7, SINUMERIK 840D sl V4.8 SINUMERIK 808D V4.8 : All versions
SINUMERIK 808D V4.7, SINUMERIK 808D V4.8, SINUMERIK 828D V4.7, SINUMERIK 840D sl V4.7, SINUMERIK 840D sl V4.8 SINUMERIK 828D V4.7 : All versions < V4.7 SP6 HF1 < SINUMERIK 828D V4.7 : All versions V4.7 SP6 HF1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved