Buffer Overflow Vulnerability in SINUMERIK 808D and 840D Series by Siemens
CVE-2018-11463
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 12 December 2018
Summary
A vulnerability exists in various versions of Siemens SINUMERIK products, where a buffer overflow in the service command application allows for potential local exploitation. This could enable an attacker with local access to execute arbitrary code with elevated privileges without requiring user interaction. The issue may compromise system confidentiality, integrity, and availability, posing significant security risks if not mitigated.
Affected Version(s)
SINUMERIK 808D V4.7, SINUMERIK 808D V4.8, SINUMERIK 828D V4.7, SINUMERIK 840D sl V4.7, SINUMERIK 840D sl V4.8 SINUMERIK 808D V4.7 : All versions
SINUMERIK 808D V4.7, SINUMERIK 808D V4.8, SINUMERIK 828D V4.7, SINUMERIK 840D sl V4.7, SINUMERIK 840D sl V4.8 SINUMERIK 808D V4.8 : All versions
SINUMERIK 808D V4.7, SINUMERIK 808D V4.8, SINUMERIK 828D V4.7, SINUMERIK 840D sl V4.7, SINUMERIK 840D sl V4.8 SINUMERIK 828D V4.7 : All versions < V4.7 SP6 HF1 < SINUMERIK 828D V4.7 : All versions V4.7 SP6 HF1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved