PT-2015-3361 · Siemens · En100 Ethernet Module Profinet Io+5

Dmitry Sklyarov

+1

·

Publicado

2015-12-17

·

Atualizado

2021-07-13

·

CVE-2018-4840

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions DIGSI 4 versions prior to V4.92 EN100 Ethernet module DNP3 variant versions prior to V1.05.00 EN100 Ethernet module IEC 104 variant (all versions) EN100 Ethernet module IEC 61850 variant versions prior to V4.30 EN100 Ethernet module Modbus TCP variant (all versions) EN100 Ethernet module PROFINET IO variant (all versions)
Description A vulnerability allows an unauthenticated remote user to upload a modified device configuration, overwriting access authorization passwords. This issue is related to inadequate access control in the device engineering mechanism. Exploitation of the vulnerability may allow a remote attacker to gain full control over the device by uploading a modified configuration file that overwrites access passwords.
Recommendations For DIGSI 4 versions prior to V4.92, update to version V4.92 or later. For EN100 Ethernet module DNP3 variant versions prior to V1.05.00, update to version V1.05.00 or later. For EN100 Ethernet module IEC 104 variant, restrict access to the device until a fix is available. For EN100 Ethernet module IEC 61850 variant versions prior to V4.30, update to version V4.30 or later. For EN100 Ethernet module Modbus TCP variant, restrict access to the device until a fix is available. For EN100 Ethernet module PROFINET IO variant, restrict access to the device until a fix is available.

Correção

Missing Authentication

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00555
CVE-2018-4840

Produtos afetados

Digsi 4
En100 Ethernet Module Dnp3
En100 Ethernet Module Iec 104
En100 Ethernet Module Iec 61850
En100 Ethernet Module Modbus Tcp
En100 Ethernet Module Profinet Io