CVE-2018-11451: Input Validation
A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firmware variant PROFINET IO for EN100 Ethernet module (All versions), Firmware variant Modbus TCP for EN100 Ethernet module (All versions), Firmware variant DNP3 TCP for EN100 Ethernet module (All versions), Firmware variant IEC104 for EN100 Ethernet module (All versions < V1.22), SIPROTEC 5 relays with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions < V7.80), SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules (All versions < V7.58). Specially crafted packets to port 102/tcp could cause a denial-of-service condition in the affected products. A manual restart is required to recover the EN100 module functionality of the affected devices. Successful exploitation requires an attacker with network access to send multiple packets to the affected products or modules. As a precondition the IEC 61850-MMS communication needs to be activated on the affected products or modules. No user interaction or privileges are required to exploit the vulnerability. The vulnerability could allow causing a Denial-of-Service condition of the network functionality of the device, compromising the availability of the system. At the time of advisory publication no public exploitation of this security vulnerability was known.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-11451?
CVE-2018-11451 is a vulnerability identified in the Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firmware variant PROFINET IO for EN100 Ethernet module (All versions), Firmware variant Modbus TCP for EN100 Ethernet module (All versions), Firmware variant DNP3 TCP for EN100 Ethernet module (All versions).
What is the severity of CVE-2018-11451?
The severity of CVE-2018-11451 is high, with a severity score of 7.5.
Which software versions are affected by CVE-2018-11451?
CVE-2018-11451 affects the following software versions: Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firmware variant PROFINET IO for EN100 Ethernet module (All versions), Firmware variant Modbus TCP for EN100 Ethernet module (All versions), Firmware variant DNP3 TCP for EN100 Ethernet module (All versions).
How can I fix CVE-2018-11451?
To fix CVE-2018-11451, it is recommended to update the firmware to a version higher than V4.33 for IEC 61850, PROFINET IO, Modbus TCP, and DNP3 TCP for the EN100 Ethernet module.
Where can I find more information about CVE-2018-11451?
More information about CVE-2018-11451 can be found at the following references: - [Siemens Productcert](https://cert-portal.siemens.com/productcert/pdf/ssa-325546.pdf) - [Siemens Productcert](https://cert-portal.siemens.com/productcert/pdf/ssa-635129.pdf) - [SecurityFocus](https://www.securityfocus.com/bid/106221)