PT-2018-1120 · Siemens · Tim 1531 Irc

Published

2018-03-27

·

Updated

2023-03-24

·

CVE-2018-4841

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TIM 1531 IRC versions prior to V1.1
Description A remote attacker with network access to port 80/tcp or port 443/tcp could perform administrative operations on the device without prior authentication. Successful exploitation could allow causing a denial-of-service, or reading and manipulating data as well as configuration settings of the affected device. The issue is related to the incorrect implementation of the authentication algorithm. At the stage of publishing this security advisory, no public exploitation is known.
Recommendations For versions prior to V1.1, Siemens provides mitigations to resolve the issue. As a temporary workaround, consider restricting access to ports 80/tcp and 443/tcp until a patch is available.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2018-00541
CVE-2018-4841

Affected Products

Tim 1531 Irc