ZeroHour

CVE-2018-4833

CVSS 3.0
8.8 high
EPSS
<1%p59
Published
()
Modified
Description

A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.6), SCALANCE X-300 switch family (incl. SIPLUS NET variants) (All versions < V4.1.3), SCALANCE X408 (All versions < V4.1.3), SCALANCE X414 (All versions), SIMATIC RF182C (All versions). Unprivileged remote attackers located in the same local network segment (OSI Layer 2) could gain remote code execution on the affected products by sending a specially crafted DHCP response to a client's DHCP request.

Vendors
siemens
Products
rfid 181-eip firmware, ruggedcom wimax firmware, scalance x200 firmware, scalance x200irt firmware, scalance x204rna firmware, scalance x300 firmware, scalance x408 firmware, scalance x414 firmware, simatic rf182c firmware
Weakness
CWE-122, CWE-20
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.