Authentication bypass in Siemens products - CVE-2018-13804
Published: November 13, 2018 / Updated: November 14, 2018
Vulnerability identifier: #VU15895
CSH Severity: Low
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-13804
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication on the target system.
The vulnerability exists due to improper authentication. A remote attacker can with network access to the installation can bypass the application-level authentication and conduct further attacks.
Affected software
SIMATIC IT UA Discrete Manufacturing
SIMATIC IT LMS
SIMATIC IT Production Suite
SIMATIC IT LMS
SIMATIC IT Production Suite
How to mitigate CVE-2018-13804
Install update from vendor's website.