MEDIUM · 5.3

CVE-2018-4839

A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Etherne...

Vulnerability Description

A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions), Other SIPROTEC 4 relays (All versions), Other SIPROTEC Compact relays (All versions), SIPROTEC 4 7SD80 (All versions < V4.70), SIPROTEC 4 7SJ61 (All versions < V4.96), SIPROTEC 4 7SJ62 (All versions < V4.96), SIPROTEC 4 7SJ64 (All versions < V4.96), SIPROTEC 4 7SJ66 (All versions < V4.30), SIPROTEC Compact 7SJ80 (All versions < V4.77), SIPROTEC Compact 7SK80 (All versions < V4.77). An attacker with local access to the engineering system or in a privileged network position and able to obtain certain network traffic could possibly reconstruct access authorization passwords.

CVSS Score

5.3

MEDIUM

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
SiemensSiprotec Compact 7Sj80 Firmware< 4.77
SiemensSiprotec Compact 7Sj80-
SiemensSiprotec Compact 7Sk80 Firmware< 4.77
SiemensSiprotec Compact 7Sk80-
SiemensSiprotec 4 7Sj66 Firmware< 4.30
SiemensSiprotec 4 7Sj66-
SiemensDigsi 4< 4.92
SiemensEn100 Ethernet Module Iec 104 Firmware-
SiemensEn100 Ethernet Module Iec 104-
SiemensEn100 Ethernet Module Dnp3 Firmware-
SiemensEn100 Ethernet Module Dnp3-
SiemensEn100 Ethernet Module Modbus Tcp Firmware-
SiemensEn100 Ethernet Module Modbus Tcp-
SiemensEn100 Ethernet Module Profinet Io Firmware-
SiemensEn100 Ethernet Module Profinet Io-
SiemensEn100 Ethernet Module Iec 61850 Firmware< 4.30
SiemensEn100 Ethernet Module Iec 61850-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-4839?

CVE-2018-4839 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Etherne...

How severe is CVE-2018-4839?

CVE-2018-4839 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-4839?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Siprotec Compact 7Sj80 Firmware, Siemens Siprotec Compact 7Sj80, Siemens Siprotec Compact 7Sk80 Firmware, Siemens Siprotec Compact 7Sk80, Siemens Siprotec 4 7Sj66 Firmware.