Authentication bypass in Siemens products - CVE-2018-4834
Published: January 26, 2018
Vulnerability identifier: #VU10253
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2018-4834
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Siemens
Affected software:
Desigo Operator Unit PXM20-E
Desigo Automation Controllers for Integration PXC001-E.D
Desigo Automation Controllers PXC00/64/128-U
Desigo Automation Controllers Modular PXC00/50/100/200-E.D
Desigo Automation Controllers Compact PXC12/22/36-E.D
Desigo Operator Unit PXM20-E
Desigo Automation Controllers for Integration PXC001-E.D
Desigo Automation Controllers PXC00/64/128-U
Desigo Automation Controllers Modular PXC00/50/100/200-E.D
Desigo Automation Controllers Compact PXC12/22/36-E.D
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication on the target system.
The weakness exists in Siemens Desigo PXC devices due to insufficient authentication checks. A remote attacker can bypass authentication and upload malicious firmware for further attacks.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists in Siemens Desigo PXC devices due to insufficient authentication checks. A remote attacker can bypass authentication and upload malicious firmware for further attacks.
Successful exploitation of the vulnerability may result in system compromise.
How to mitigate CVE-2018-4834
Update to version 6.00.204.