CVE-2018-4858
Last modified
CVE-2018-4858 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A vulnerability has been identified in IEC 61850 system configurator (All versions < V5.80), DIGSI 5 (affected as IEC 61850 system configurator is incorporated) (All versions < V7.80), DIGSI 4 (All versions < V4.93), SICAM PAS/PQS (All versions < V8.11), SICAM PQ Analyzer (All versions < V3.11), SICAM SCC (All versions < V9.02 HF3). A service of the affected products listening on all of the host's network interfaces on either port 4884/TCP, 5885/TCP, or port 5886/TCP could allow an attacker to either exfiltrate limited data from the system or to execute code with Microsoft Windows user permissions. EPSS estimates a 1.84% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in IEC 61850 system configurator (All versions < V5.80), DIGSI 5 (affected as IEC 61850 system configurator is incorporated) (All versions < V7.80), DIGSI 4 (All versions < V4.93), SICAM PAS/PQS (All versions < V8.11), SICAM PQ Analyzer (All versions < V3.11), SICAM SCC (All versions < V9.02 HF3). A service of the affected products listening on all of the host's network interfaces on either port 4884/TCP, 5885/TCP, or port 5886/TCP could allow an attacker to either exfiltrate limited data from the system or to execute code with Microsoft Windows user permissions. Successful exploitation requires an attacker to be able to send a specially crafted network request to the vulnerable service and a user interacting with the service's client application on the host. In order to execute arbitrary code with Microsoft Windows user permissions, an attacker must be able to plant the code in advance on the host by other means. The vulnerability has limited impact to confidentiality and integrity of the affected system. At the time of advisory publication no public exploitation of this security vulnerability was known. Siemens confirms the security vulnerability and provides mitigations to resolve the security issue.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Ec 61850 System Configurator Firmware | < 5.80 |
| Siemens | Sicam Pq Analyzer Firmware | < 3.11 |
| Siemens | Sicam Scc Firmware | All versions |
| Siemens | Digsi 4 Firmware | All versions |
| Siemens | Digsi 5 Firmware | < 7.80 |
| Siemens | Sicam Pas\/Pqs | < 8.11 |
References
- http://www.securityfocus.com/bid/105933Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-317-01Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/105933Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-317-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-4858?
How severe is CVE-2018-4858?
How do I fix CVE-2018-4858?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-4852A vulnerability has been identified in SICLOCK TC100 (All ve…
- CVE-2018-4853A vulnerability has been identified in SICLOCK TC100 (All ve…
- CVE-2018-4854A vulnerability has been identified in SICLOCK TC100 (All ve…
- CVE-2018-4855A vulnerability has been identified in SICLOCK TC100 (All ve…
- CVE-2018-4856A vulnerability has been identified in SICLOCK TC100 (All ve…
- CVE-2018-4857Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-4859A vulnerability has been identified in SCALANCE M875 (All ve…
- CVE-2018-4860A vulnerability has been identified in SCALANCE M875 (All ve…
- CVE-2018-4861A vulnerability has been identified in SCALANCE M875 (All ve…
- CVE-2018-4862In Octopus Deploy versions 3.2.11 - 4.1.5 (fixed in 4.1.6), …
- CVE-2018-4863Sophos Endpoint Protection 10.7 allows local users to bypass…
- CVE-2018-4868The Exiv2::Jp2Image::readMetadata function in jp2image.cpp i…
Are you affected by CVE-2018-4858?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
