PT-2018-2193 · Siemens · Sinumerik 828D+1
Published
2018-12-11
·
Updated
2019-10-09
·
CVE-2018-11457
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SINUMERIK 828D V4.7 versions prior to V4.7 SP6 HF1
SINUMERIK 840D sl V4.7 versions prior to V4.7 SP6 HF5
SINUMERIK 840D sl V4.8 versions prior to V4.8 SP3
Description
The issue is related to a dynamic memory overflow in the Siemens Sinumerik CNC software. Exploitation of this issue could allow a remote attacker to execute arbitrary code with privileged permissions by sending specially crafted network requests to port 4842/TCP. The integrated web server on this port could be exploited if it is manually opened in the firewall configuration. Successful exploitation requires no privileges and no user interaction, potentially compromising the confidentiality, integrity, and availability of the web server.
Recommendations
For SINUMERIK 828D V4.7 versions prior to V4.7 SP6 HF1, update to V4.7 SP6 HF1 or later to resolve the issue.
For SINUMERIK 840D sl V4.7 versions prior to V4.7 SP6 HF5, update to V4.7 SP6 HF5 or later to resolve the issue.
For SINUMERIK 840D sl V4.8 versions prior to V4.8 SP3, update to V4.8 SP3 or later to resolve the issue.
As a temporary workaround, consider restricting access to port 4842/TCP to minimize the risk of exploitation.
Fix
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sinumerik 828D
Sinumerik 840D Sl