PT-2018-2201 · Siemens · Sinumerik 828D+2
Published
2018-12-11
·
Updated
2019-10-09
·
CVE-2018-11465
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SINUMERIK 808D V4.7
SINUMERIK 808D V4.8
SINUMERIK 828D versions prior to V4.7 SP6 HF1
SINUMERIK 840D sl versions prior to V4.7 SP6 HF5
SINUMERIK 840D sl versions prior to V4.8 SP3
Description
A local attacker could use ioctl calls to perform out of bounds reads, arbitrary writes, or execute code in kernel mode. The security issue could be exploited by an attacker with local access to the affected systems, requiring user privileges but no user interaction. This could allow an attacker to compromise confidentiality, integrity, and availability of the system. At the time of advisory publication, no public exploitation of this security issue was known.
Recommendations
For SINUMERIK 808D V4.7, update to a version later than V4.7.
For SINUMERIK 808D V4.8, update to a version later than V4.8 SP3.
For SINUMERIK 828D, update to V4.7 SP6 HF1 or later.
For SINUMERIK 840D sl V4.7, update to V4.7 SP6 HF5 or later.
For SINUMERIK 840D sl V4.8, update to V4.8 SP3 or later.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sinumerik 808D
Sinumerik 828D
Sinumerik 840D Sl