Security restrictions bypass in Siemens products - CVE-2018-4858
Published: November 13, 2018 / Updated: November 14, 2018
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists due to improper access control. A remote unauthenticated attacker can bypass security restrictions to exfiltrate limited data from the system or execute code with operating system user permissions.
Affected software
SICAM SCC
SICAM PQ Analyzer
SICAM PAS/PQS
DIGSI 5
IEC 61850 system configurator
How to mitigate CVE-2018-4858
SICAM SCC - update to 9.02 HF3
SICAM PQ Analyzer - update to 3.11
SICAM PAS/PQS - update to 8.11
DIGSI 5 - update to 7.80
IEC 61850 system configurator - update to 5.80