Local Access Vulnerability in Siemens DIGSI 4 and SIPROTEC Relays
CVE-2018-4839
5.3MEDIUM
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 8 March 2018
Summary
A local access vulnerability has been discovered in Siemens DIGSI 4 and several SIPROTEC relay models. An attacker with local access to the engineering system, or positioned within a privileged network, could exploit this vulnerability to reconstruct access authorization passwords by obtaining specific network traffic. This creates a potential risk for unauthorized access and manipulation of system configurations, highlighting the importance of securing access points and monitoring network traffic in environments utilizing these devices.
Affected Version(s)
DIGSI 4 All versions < V4.92
EN100 Ethernet module DNP3 variant All versions < V1.05.00
EN100 Ethernet module IEC 104 variant All versions
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved