Local Access Vulnerability in Siemens DIGSI 4 and SIPROTEC Relays
CVE-2018-4839

5.3MEDIUM

Summary

A local access vulnerability has been discovered in Siemens DIGSI 4 and several SIPROTEC relay models. An attacker with local access to the engineering system, or positioned within a privileged network, could exploit this vulnerability to reconstruct access authorization passwords by obtaining specific network traffic. This creates a potential risk for unauthorized access and manipulation of system configurations, highlighting the importance of securing access points and monitoring network traffic in environments utilizing these devices.

Affected Version(s)

DIGSI 4 All versions < V4.92

EN100 Ethernet module DNP3 variant All versions < V1.05.00

EN100 Ethernet module IEC 104 variant All versions

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.