HIGH · 8.8

CVE-2018-4833

A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANC...

Vulnerability Description

A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.6), SCALANCE X-300 switch family (incl. SIPLUS NET variants) (All versions < V4.1.3), SCALANCE X408 (All versions < V4.1.3), SCALANCE X414 (All versions), SIMATIC RF182C (All versions). Unprivileged remote attackers located in the same local network segment (OSI Layer 2) could gain remote code execution on the affected products by sending a specially crafted DHCP response to a client's DHCP request.

CVSS Score

8.8

HIGH

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SiemensRfid 181-Eip Firmware-
SiemensRfid 181-Eip-
SiemensRuggedcom Wimax Firmware4.4
SiemensRuggedcom Wimax-
SiemensScalance X200 Firmware< 5.2.3
SiemensScalance X200-
SiemensScalance X200Irt Firmware< 5.4.1
SiemensScalance X200Irt-
SiemensScalance X204Rna Firmware-
SiemensScalance X204Rna-
SiemensScalance X300 Firmware-
SiemensScalance X300-
SiemensScalance X408 Firmware-
SiemensScalance X408-
SiemensScalance X414 Firmware-
SiemensScalance X414-
SiemensSimatic Rf182C Firmware-
SiemensSimatic Rf182C-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-4833?

CVE-2018-4833 is a vulnerability with a CVSS score of 8.8 (HIGH). A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANC...

How severe is CVE-2018-4833?

CVE-2018-4833 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-4833?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Rfid 181-Eip Firmware, Siemens Rfid 181-Eip, Siemens Ruggedcom Wimax Firmware, Siemens Ruggedcom Wimax, Siemens Scalance X200 Firmware.