HTTP header injection in Siemens products - CVE-2018-13814

 

HTTP header injection in Siemens products - CVE-2018-13814

Published: November 13, 2018 / Updated: November 14, 2018


Vulnerability identifier: #VU15889
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-13814
CWE-ID: CWE-113
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject HTTP header on the target system.

The vulnerability exists due to insufficient validation of user-supplied input. A remote unauthenticated attacker can trick the victim into clicking on a malicious link and use integrated web server (Port 80/TCP and Port 443/TCP) inject HTTP headers.


Affected software

SIMATIC HMI Comfort Panels 4”-22”
SIMATIC HMI Comfort Outdoor Panels 7” & 15”
SIMATIC HMI KTP900F
SIMATIC HMI KTP900
SIMATIC HMI KTP700F
SIMATIC HMI KTP700
SIMATIC HMI KTP400F
SIMATIC WinCC Runtime Professional
SIMATIC WinCC Runtime Advanced
SIMATIC WinCC (TIA Portal)
SIMATIC HMI MP Mobile Panel
SIMATIC HMI OP
SIMATIC HMI MP
SIMATIC HMI TP

How to mitigate CVE-2018-13814

Update all affected products to version 15 Update 4.

SIMATIC HMI Comfort Panels 4”-22” - update to 15 Update 4
SIMATIC HMI Comfort Outdoor Panels 7” & 15” - update to 15 Update 4
SIMATIC HMI KTP900F - update to 15 Update 4
SIMATIC HMI KTP900 - update to 15 Update 4
SIMATIC HMI KTP700F - update to 15 Update 4
SIMATIC HMI KTP700 - update to 15 Update 4
SIMATIC HMI KTP400F - update to 15 Update 4
SIMATIC WinCC Runtime Professional - update to 15 Update 4
SIMATIC WinCC Runtime Advanced - update to 15 Update 4
SIMATIC WinCC (TIA Portal) - update to 15 Update 4
SIMATIC HMI MP Mobile Panel - update to 15 Update 4
SIMATIC HMI OP - update to 15 Update 4
SIMATIC HMI MP - update to 15 Update 4
SIMATIC HMI TP - update to 15 Update 4

External References

Related Security Bulletins