PT-2018-1569 · Siemens · Scalance X414+2

Published

2018-09-11

·

Updated

2019-10-09

·

CVE-2018-13807

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SCALANCE X300 versions prior to 4.0.0 SCALANCE X408 versions prior to 4.0.0 SCALANCE X414 (all versions)
Description A vulnerability has been identified that could allow an attacker to cause a Denial-of-Service condition by sending specially crafted packets to the web server on port 443/tcp. This would cause the device to automatically reboot, impacting network availability for other devices. An attacker must have network access to port 443/tcp to exploit the issue. Neither valid credentials nor interaction by a legitimate user is required. The vulnerability is related to insufficient input validation and could be triggered by publicly available tools, temporarily impacting availability.
Recommendations For SCALANCE X300 versions prior to 4.0.0, update to version 4.0.0 or later. For SCALANCE X408 versions prior to 4.0.0, update to version 4.0.0 or later. For SCALANCE X414, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the web interface on port 443/tcp to minimize the risk of exploitation.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01126
CVE-2018-13807

Affected Products

Scalance X-300
Scalance X 408
Scalance X414