PT-2018-16576 · Siemens · Scalance M875

Published

2018-06-26

·

Updated

2019-10-09

·

CVE-2018-4859

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SCALANCE M875 (All versions)
Description A security issue has been identified that allows an authenticated remote attacker with access to the web interface (443/tcp) to execute arbitrary operating system commands. The attacker must have network access to the web interface and be authenticated as an administrative user. This could allow the attacker to execute arbitrary code on the device. There are no known public exploits of this issue at the time of publication.
Recommendations For SCALANCE M875, restrict access to the web interface to minimize the risk of exploitation. As a temporary workaround, consider limiting administrative user access until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-4859

Affected Products

Scalance M875