Network Access Vulnerability in Siemens CP 1604 and CP 1616 Products
CVE-2018-13808

9.1CRITICAL

Key Information:

Vendor
Siemens
Vendor
CVE Published:
17 April 2019

Summary

A network access vulnerability has been discovered in Siemens CP 1604 and CP 1616 products that allows an attacker to potentially extract internal communication data or initiate a Denial-of-Service (DoS) condition. This vulnerability can be exploited by an attacker with access to port 23/tcp on vulnerable devices. At the time of the advisory's publication, there was no known public exploitation of this risk. It's crucial for users of these systems to apply appropriate security measures to mitigate any potential impact.

Affected Version(s)

CP 1604 All versions

CP 1616 All versions

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.