Heap-based buffer overflow in Siemens products - CVE-2018-11457
Published: December 11, 2018 / Updated: December 12, 2018
SINUMERIK 808D
SINUMERIK 840D
SINUMERIK 828D
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to heap-based buffer overflow when handling malicious input if Port 4842/TCP is manually opened in the firewall configuration of network Port X130. A remote unauthenticated attacker can specially crafted network requests to Port 4842/TCP, trigger memory corruption and execute arbitrary code with privileged permissions.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
How to mitigate CVE-2018-11457
Update SINUMERIK 840D to version 4.7 SP6 HF5 or 4.8 SP3.