CVE-2018-16563
Last modified
CVE-2018-16563 is a vulnerability of currently unknown severity. A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.35), Firmware variant MODBUS TCP for EN100 Ethernet module (All versions), Firmware variant DNP3 TCP for EN100 Ethernet module (All versions), Firmware variant IEC104 for EN100 Ethernet module (All versions), Firmware variant Profinet IO for EN100 Ethernet module (All versions), SIPROTEC 5 relays with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions < V7.82), SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules (All versions < V7.58). Specially crafted packets to port 102/tcp could cause a denial-of-service condition in the affected products. EPSS estimates a 1.16% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.35), Firmware variant MODBUS TCP for EN100 Ethernet module (All versions), Firmware variant DNP3 TCP for EN100 Ethernet module (All versions), Firmware variant IEC104 for EN100 Ethernet module (All versions), Firmware variant Profinet IO for EN100 Ethernet module (All versions), SIPROTEC 5 relays with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions < V7.82), SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules (All versions < V7.58). Specially crafted packets to port 102/tcp could cause a denial-of-service condition in the affected products. A manual restart is required to recover the EN100 module functionality of the affected devices. Successful exploitation requires an attacker with network access to send multiple packets to the affected products or modules. As a precondition the IEC 61850-MMS communication needs to be activated on the affected products or modules. No user interaction or privileges are required to exploit the vulnerability. The vulnerability could allow causing a Denial-of-Service condition of the network functionality of the device, compromising the availability of the system. At the time of advisory publication no public exploitation of this security vulnerability was known.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Siprotec 5 With Cpu Variant Cp100 | < 7.82 |
| Siemens | Siprotec 5 With Cpu Variant Cp200 | < 7.58 |
| Siemens | Siprotec 5 With Cpu Variant Cp300 | < 7.82 |
| Siemens | En100 Ethernet Module Firmware | All versions |
| Siemens | En100 Ethernet Module With Firmware Variant Dnp3 Tcp | All versions |
| Siemens | En100 Ethernet Module With Firmware Variant Iec 61850 | 4.35 |
| Siemens | En100 Ethernet Module With Firmware Variant Iec104 | All versions |
| Siemens | En100 Ethernet Module With Firmware Variant Modbus Tcp | All versions |
| Siemens | En100 Ethernet Module With Firmware Variant Profinet Io | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-16563?
How severe is CVE-2018-16563?
How do I fix CVE-2018-16563?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-16558A vulnerability has been identified in SIMATIC S7-1500 CPU (…
- CVE-2018-16559A vulnerability has been identified in SIMATIC S7-1500 CPU (…
- CVE-2018-1656The IBM Java Runtime Environment's Diagnostic Tooling Framew…7.4
- CVE-2018-16560Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-16561A vulnerability has been identified in SIMATIC S7-300 CPUs (…7.5
- CVE-2018-16562Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-16564Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-16565Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-16566Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-16567Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-16568Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-16569Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2018-16563?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
