5
CVSSv2

CVE-2018-4838

Published: 08/03/2018 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability has been identified in EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module DNP3 variant (All versions < V1.04), EN100 Ethernet module PROFINET IO variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions < V1.22). The web interface (TCP/80) of affected devices allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to older versions with known vulnerabilities.

Vulnerable Product Search on Vulmon Subscribe to Product

siemens en100_ethernet_module_iec_104_firmware -

siemens en100_ethernet_module_dnp3_firmware -

siemens en100_ethernet_module_modbus_tcp_firmware -

siemens en100_ethernet_module_profinet_io_firmware -

siemens en100_ethernet_module_iec_61850_firmware