Stack-based buffer overflow in Siemens products - CVE-2018-11463
Published: December 12, 2018
SINUMERIK 808D
SINUMERIK 840D
SINUMERIK 828D
Detailed vulnerability description
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability exists due to stack-based buffer overflow in the service command application when handling malicious input. A local attacker can execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
How to mitigate CVE-2018-11463
Update SINUMERIK 840D to version 4.7 SP6 HF5 or 4.8 SP3.