Information disclosure in Siemens SCALANCE W1750D

Published: 2018-10-10 16:58:58
Severity Low
Patch available YES
Number of vulnerabilities 1
CVE ID CVE-2017-13099
CVSSv3 5.2 [CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]
CWE ID CWE-300
Exploitation vector Network
Public exploit N/A
Vulnerable software SCALANCE W1750D
Vulnerable software versions SCALANCE W1750D -
Vendor URL Siemens

Security Advisory

1) Man-in-the-middle attack

Description

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The vulnerability exists due to man-in-the-middle attack. A remote attacker can conduct MITM-attack, observe TLS traffic between a legitimate user and the device and decrypt the TLS traffic.

Remediation

Update to version 8.3.0.1.

External links

https://cert-portal.siemens.com/productcert/pdf/ssa-464260.pdf

Back to List