Uncaught exception in Siemens products - CVE-2018-11466
Published: December 12, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition or execute arbitrary code on the target system.
The vulnerability exists due to uncaught exception. A remote unauthenticated attacker can send specially crafted network packets to Port 102/TCP (ISO-TSAP), cause a denial-of-service condition of the integrated software firewall or execute code in the context of the software firewall.
Affected software
SINUMERIK 840D
SINUMERIK 828D
How to mitigate CVE-2018-11466
Update SINUMERIK 840D to version 4.7 SP6 HF5 or 4.8 SP3.
SINUMERIK 840D - addressed in versions 4.7 SP6 HF5, 4.8 SP3