HIGH · 7.5

CVE-2018-4840

A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Etherne...

Vulnerability Description

A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions). The device engineering mechanism allows an unauthenticated remote user to upload a modified device configuration overwriting access authorization passwords.

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
SiemensSiprotec Compact 7Sj80 Firmware< 4.77
SiemensSiprotec Compact 7Sj80-
SiemensSiprotec Compact 7Sk80 Firmware< 4.77
SiemensSiprotec Compact 7Sk80-
SiemensSiprotec 4 7Sj66 Firmware< 4.30
SiemensSiprotec 4 7Sj66-
SiemensDigsi 4< 4.92
SiemensEn100 Ethernet Module Iec 104 Firmware-
SiemensEn100 Ethernet Module Iec 104-
SiemensEn100 Ethernet Module Dnp3 Firmware-
SiemensEn100 Ethernet Module Dnp3-
SiemensEn100 Ethernet Module Modbus Tcp Firmware-
SiemensEn100 Ethernet Module Modbus Tcp-
SiemensEn100 Ethernet Module Profinet Io Firmware-
SiemensEn100 Ethernet Module Profinet Io-
SiemensEn100 Ethernet Module Iec 61850 Firmware< 4.30
SiemensEn100 Ethernet Module Iec 61850-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-4840?

CVE-2018-4840 is a vulnerability with a CVSS score of 7.5 (HIGH). A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Etherne...

How severe is CVE-2018-4840?

CVE-2018-4840 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-4840?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Siprotec Compact 7Sj80 Firmware, Siemens Siprotec Compact 7Sj80, Siemens Siprotec Compact 7Sk80 Firmware, Siemens Siprotec Compact 7Sk80, Siemens Siprotec 4 7Sj66 Firmware.