SB2018033103 - Security restrictions bypass in Siemens TIM 1531 IRC
Published: March 31, 2018
Security Bulletin ID
SB2018033103
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2018-4841)
The vulnerability allows a remote attacker to bypass security restrictions.The weakness exists due to incorrect implementation of authentication algorithm. A remote attacker with network access to Port 80/TCP or Port 443/TCP can bypass security restrictions and perform administrative operations on the device, cause DoS condition, gain read or write access to arbitrary data on the target system.
Remediation
Install update from vendor's website.