CVE-2018-13804

Published: Dic 13, 2018 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2018-5740 Aliases: GSD-2018-13804
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,1
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
HIGH 9,3
Access Vector: network
Access Complexity: medium
Authentication: none
Confidentiality: complete
Integrity: complete
Availability: complete

Description

AI Translation Available

A vulnerability has been identified in SIMATIC IT LMS (All versions), SIMATIC IT Production Suite (Versions V7.1 < V7.1 Upd3), SIMATIC IT UA Discrete Manufacturing (Versions < V1.2), SIMATIC IT UA Discrete Manufacturing (Versions V1.2), SIMATIC IT UA Discrete Manufacturing (Versions V1.3), SIMATIC IT UA Discrete Manufacturing (Versions V2.3), SIMATIC IT UA Discrete Manufacturing (Versions V2.4). An attacker with network access to the installation could bypass the application-level authentication. In order to exploit the vulnerability, an attacker must obtain network access to an affected installation and must obtain a valid username to the system. Successful exploitation requires no user privileges and no user interaction. The vulnerability could allow an attacker to compromise confidentiality, integrity and availability of the system. At the time of advisory publication no public exploitation of this vulnerability was known.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0338
Percentile
0,9th
Updated

EPSS Score Trend (Last 90 Days)

287

Improper Authentication

Draft
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability Access Control
Potential Impacts:
Read Application Data Gain Privileges Or Assume Identity Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies: ICS/OT, Not Technology-Specific, Web Based
View CWE Details
Application

Simatic It Production Suite by Siemens

cpe:2.3:a:siemens:simatic_it_production_suite:v7.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Simatic It Ua Discrete Manufacturing by Siemens

cpe:2.3:a:siemens:simatic_it_ua_discrete_manufacturing:v2.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Simatic It Ua Discrete Manufacturing by Siemens

cpe:2.3:a:siemens:simatic_it_ua_discrete_manufacturing:v2.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Simatic It Line Monitoring System by Siemens

cpe:2.3:a:siemens:simatic_it_line_monitoring_system:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Simatic It Ua Discrete Manufacturing by Siemens

cpe:2.3:a:siemens:simatic_it_ua_discrete_manufacturing:v1.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Simatic It Ua Discrete Manufacturing by Siemens

Version Range Affected
To v1.2 (inclusive)
cpe:2.3:a:siemens:simatic_it_ua_discrete_manufacturing:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://cert-portal.siemens.com/productcert/pdf/ssa-886615.pdf
http://www.securityfocus.com/bid/105924
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/105924
https://cert-portal.siemens.com/productcert/pdf/ssa-886615.pdf
http://www.securityfocus.com/bid/105924
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/105924