Vulnerability Description
A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.6), SCALANCE X-300 switch family (incl. SIPLUS NET variants) (All versions < V4.1.3), SCALANCE X408 (All versions < V4.1.3), SCALANCE X414 (All versions), SIMATIC RF182C (All versions). Unprivileged remote attackers located in the same local network segment (OSI Layer 2) could gain remote code execution on the affected products by sending a specially crafted DHCP response to a client's DHCP request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Rfid 181-Eip Firmware | - |
| Siemens | Rfid 181-Eip | - |
| Siemens | Ruggedcom Wimax Firmware | 4.4 |
| Siemens | Ruggedcom Wimax | - |
| Siemens | Scalance X200 Firmware | < 5.2.3 |
| Siemens | Scalance X200 | - |
| Siemens | Scalance X200Irt Firmware | < 5.4.1 |
| Siemens | Scalance X200Irt | - |
| Siemens | Scalance X204Rna Firmware | - |
| Siemens | Scalance X204Rna | - |
| Siemens | Scalance X300 Firmware | - |
| Siemens | Scalance X300 | - |
| Siemens | Scalance X408 Firmware | - |
| Siemens | Scalance X408 | - |
| Siemens | Scalance X414 Firmware | - |
| Siemens | Scalance X414 | - |
| Siemens | Simatic Rf182C Firmware | - |
| Siemens | Simatic Rf182C | - |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-181018.pdfVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-181018.pdfVendor Advisory
FAQ
What is CVE-2018-4833?
CVE-2018-4833 is a vulnerability with a CVSS score of 8.8 (HIGH). A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANC...
How severe is CVE-2018-4833?
CVE-2018-4833 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-4833?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Rfid 181-Eip Firmware, Siemens Rfid 181-Eip, Siemens Ruggedcom Wimax Firmware, Siemens Ruggedcom Wimax, Siemens Scalance X200 Firmware.