PT-2018-2196 · Siemens · Sinumerik 828D+2
Publicado
2018-12-11
·
Atualizado
2019-10-09
·
CVE-2018-11460
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SINUMERIK 808D V4.7
SINUMERIK 808D V4.8
SINUMERIK 828D versions prior to V4.7 SP6 HF1
SINUMERIK 840D sl versions prior to V4.7 SP6 HF5
SINUMERIK 840D sl versions prior to V4.8 SP3
Description
A local attacker with elevated user privileges could modify a CRAMFS archive, allowing attacker-controlled code to be executed with root privileges after reboot. The vulnerability could be exploited by an attacker with local access to the affected systems, requiring no user interaction but elevated user privileges. Successful exploitation could compromise confidentiality, integrity, and availability of the system. At the time of advisory publication, no public exploitation of this security issue was known.
Recommendations
For SINUMERIK 808D V4.7, update to a version that includes the necessary security patches.
For SINUMERIK 808D V4.8, update to a version that includes the necessary security patches.
For SINUMERIK 828D, update to V4.7 SP6 HF1 or later.
For SINUMERIK 840D sl versions prior to V4.7 SP6 HF5, update to V4.7 SP6 HF5 or later.
For SINUMERIK 840D sl versions prior to V4.8 SP3, update to V4.8 SP3 or later.
Correção
Protection Mechanism Failure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sinumerik 808D
Sinumerik 828D
Sinumerik 840D Sl