PT-2018-10582 · Siemens · Wincc+1

Publicado

2018-08-07

·

Atualizado

2019-10-09

·

CVE-2018-11453

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) versions V10 through V12 SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) versions V13 through V13 SP1 Update 2 SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) versions V14 through V14 SP1 Update 5 SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) versions V15 through V15 Update 1
Description A vulnerability has been identified due to improper file permissions in the default installation of TIA Portal. This may allow an attacker with local file system access to insert specially crafted files, potentially preventing TIA Portal startup or leading to local code execution. The attacker does not require special privileges, but the victim must attempt to start TIA Portal after the manipulation.
Recommendations For versions V10 through V12, update to a version later than V12. For versions V13 through V13 SP1 Update 2, update to V13 SP2 Update 2 or later. For versions V14 through V14 SP1 Update 5, update to V14 SP1 Update 6 or later. For versions V15 through V15 Update 1, update to V15 Update 2 or later.

Correção

Incorrect Permission

Incorrect Default Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-11453

Produtos afetados

Simatic Step 7
Wincc