PT-2018-2199 · Siemens · Sinumerik 808D+2

Published

2018-12-11

·

Updated

2019-10-09

·

CVE-2018-11463

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SINUMERIK 808D V4.7 SINUMERIK 808D V4.8 SINUMERIK 828D versions prior to V4.7 SP6 HF1 SINUMERIK 840D sl versions prior to V4.7 SP6 HF5 SINUMERIK 840D sl versions prior to V4.8 SP3
Description The issue is related to a buffer overflow in the service command application, which could allow a local attacker to execute code with elevated privileges. This could compromise the confidentiality, integrity, and availability of the system. The vulnerability can be exploited by an attacker with local access to the affected systems, requiring user privileges but no user interaction. At the time of advisory publication, no public exploitation of this security vulnerability was known.
Recommendations For SINUMERIK 808D V4.7, update to a version that includes the necessary security patches. For SINUMERIK 808D V4.8, update to a version that includes the necessary security patches. For SINUMERIK 828D, update to V4.7 SP6 HF1 or later. For SINUMERIK 840D sl versions prior to V4.7 SP6 HF5, update to V4.7 SP6 HF5 or later. For SINUMERIK 840D sl versions prior to V4.8 SP3, update to V4.8 SP3 or later.

Fix

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00177
CVE-2018-11463

Affected Products

Sinumerik 808D
Sinumerik 828D
Sinumerik 840D Sl