PT-2018-1120 · Siemens · Tim 1531 Irc
Published
2018-03-27
·
Updated
2023-03-24
·
CVE-2018-4841
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TIM 1531 IRC versions prior to V1.1
Description
A remote attacker with network access to port 80/tcp or port 443/tcp could perform administrative operations on the device without prior authentication. Successful exploitation could allow causing a denial-of-service, or reading and manipulating data as well as configuration settings of the affected device. The issue is related to the incorrect implementation of the authentication algorithm. At the stage of publishing this security advisory, no public exploitation is known.
Recommendations
For versions prior to V1.1, Siemens provides mitigations to resolve the issue.
As a temporary workaround, consider restricting access to ports 80/tcp and 443/tcp until a patch is available.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tim 1531 Irc