#VU14418 Improper input validation in Siemens Automation License Manager - CVE-2018-11456
Published: August 15, 2018
Siemens Automation License Manager
Siemens
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote unauthenticated attacker can send specially crafted network packets to determine whether a network port on another remote system is accessible and do basic network scanning using the victim’s machine.