CVE-2018-5469
Last modified
CVE-2018-5469 is a vulnerability of currently unknown severity. An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An improper restriction of excessive authentication vulnerability in the web interface has been identified, which may allow an attacker to brute force authentication.. EPSS estimates a 2.93% chance of exploitation in the next 30 days.
Description
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An improper restriction of excessive authentication vulnerability in the web interface has been identified, which may allow an attacker to brute force authentication.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Belden | Hirschmann Rs20-0900mmm2tdau | All versions |
| Belden | Hirschmann Rs20-0900nnm4tdau | All versions |
| Belden | Hirschmann Rs20-0900vvm2tdau | All versions |
| Belden | Hirschmann Rs20-1600l2l2sdau | All versions |
| Belden | Hirschmann Rs20-1600l2m2sdau | All versions |
| Belden | Hirschmann Rs20-1600l2s2sdau | All versions |
| Belden | Hirschmann Rs20-1600l2t1sdau | All versions |
| Belden | Hirschmann Rs20-1600m2m2sdau | All versions |
| Belden | Hirschmann Rs20-1600m2t1sdau | All versions |
| Belden | Hirschmann Rs20-1600s2m2sdau | All versions |
| Belden | Hirschmann Rs20-1600s2s2sdau | All versions |
| Belden | Hirschmann Rs20-1600s2t1sdau | All versions |
| Belden | Hirschmann Rsr20 | All versions |
| Belden | Hirschmann Rsr30 | All versions |
| Belden | Hirschmann Rsb20-0800m2m2saab | All versions |
| Belden | Hirschmann Rsb20-0800m2m2saabe | All versions |
| Belden | Hirschmann Rsb20-0800m2m2taab | All versions |
| Belden | Hirschmann Rsb20-0800m2m2taabe | All versions |
| Belden | Hirschmann Rsb20-0800s2s2saab | All versions |
| Belden | Hirschmann Rsb20-0800s2s2saabe | All versions |
| Belden | Hirschmann Rsb20-0800s2s2taab | All versions |
| Belden | Hirschmann Rsb20-0800s2s2taabe | All versions |
| Belden | Hirschmann Rsb20-0800t1t1saab | All versions |
| Belden | Hirschmann Rsb20-0800t1t1saabe | All versions |
| Belden | Hirschmann Rsb20-0800t1t1taab | All versions |
| Belden | Hirschmann Rsb20-0800t1t1taabe | All versions |
| Belden | Hirschmann Rsb20-0900m2ttsaab | All versions |
| Belden | Hirschmann Rsb20-0900m2ttsaabe | All versions |
| Belden | Hirschmann Rsb20-0900m2tttaab | All versions |
| Belden | Hirschmann Rsb20-0900m2tttaabe | All versions |
| Belden | Hirschmann Rsb20-0900mmm2saab | All versions |
| Belden | Hirschmann Rsb20-0900mmm2saabe | All versions |
| Belden | Hirschmann Rsb20-0900mmm2taab | All versions |
| Belden | Hirschmann Rsb20-0900mmm2taabe | All versions |
| Belden | Hirschmann Rsb20-0900s2ttsaab | All versions |
| Belden | Hirschmann Rsb20-0900s2ttsaabe | All versions |
| Belden | Hirschmann Rsb20-0900s2tttaab | All versions |
| Belden | Hirschmann Rsb20-0900s2tttaabe | All versions |
| Belden | Hirschmann Rsb20-0900vvm2saab | All versions |
| Belden | Hirschmann Rsb20-0900vvm2saabe | All versions |
| Belden | Hirschmann Rsb20-0900vvm2taab | All versions |
| Belden | Hirschmann Rsb20-0900vvm2taabe | All versions |
| Belden | Hirschmann Rsb20-0900zzz6saab | All versions |
| Belden | Hirschmann Rsb20-0900zzz6saabe | All versions |
| Belden | Hirschmann Rsb20-0900zzz6taab | All versions |
| Belden | Hirschmann Rsb20-0900zzz6taabe | All versions |
| Belden | Hirschmann M1-8mm-Sc | All versions |
| Belden | Hirschmann M1-8sfp | All versions |
| Belden | Hirschmann M1-8sm-Sc | All versions |
| Belden | Hirschmann M1-8tp-Rj45 | All versions |
Showing 50 of 134 affected configurations. See NVD for the full list.
References
- http://www.securityfocus.com/bid/103340Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-065-01Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/103340Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-065-01Mitigation, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5469?
How severe is CVE-2018-5469?
How do I fix CVE-2018-5469?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5463A structured exception handler overflow vulnerability in Lea…
- CVE-2018-5464Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x…
- CVE-2018-5465A Session Fixation issue was discovered in Belden Hirschmann…
- CVE-2018-5466Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x…
- CVE-2018-5467An Information Exposure Through Query Strings in GET Request…
- CVE-2018-5468Philips Intellispace Portal all versions 7.0.x and 8.0.x hav…
- CVE-2018-5470Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x…
- CVE-2018-5471A Cleartext Transmission of Sensitive Information issue was …
- CVE-2018-5472Philips Intellispace Portal all versions 7.0.x and 8.0.x hav…
- CVE-2018-5473An Improper Restriction of Operations within the Bounds of a…9.8
- CVE-2018-5474Philips Intellispace Portal all versions 7.0.x and 8.0.x hav…
- CVE-2018-5475A Stack-based Buffer Overflow issue was discovered in GE D60…9.8
Are you affected by CVE-2018-5469?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
