SB2018033103 - Security restrictions bypass in Siemens TIM 1531 IRC



SB2018033103 - Security restrictions bypass in Siemens TIM 1531 IRC

Published: March 31, 2018

Security Bulletin ID SB2018033103
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security restrictions bypass (CVE-ID: CVE-2018-4841)

The vulnerability allows a remote attacker to bypass security restrictions.

The weakness exists due to incorrect implementation of authentication algorithm. A remote attacker with network access to Port 80/TCP or Port 443/TCP can bypass security restrictions and perform administrative operations on the device, cause DoS condition, gain read or write access to arbitrary data on the target system.

Remediation

Install update from vendor's website.