CVE-2018-11452: Input Validation
A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firmware variant PROFINET IO for EN100 Ethernet module (All versions), Firmware variant Modbus TCP for EN100 Ethernet module (All versions), Firmware variant DNP3 TCP for EN100 Ethernet module (All versions), Firmware variant IEC104 for EN100 Ethernet module (All versions < V1.22). Specially crafted packets to port 102/tcp could cause a denial-of-service condition in the EN100 communication module if oscillographs are running. A manual restart is required to recover the EN100 module functionality. Successful exploitation requires an attacker with network access to send multiple packets to the EN100 module. As a precondition the IEC 61850-MMS communication needs to be activated on the affected EN100 modules. No user interaction or privileges are required to exploit the security vulnerability. The vulnerability could allow causing a Denial-of-Service condition of the network functionality of the device, compromising the availability of the system. At the time of advisory publication no public exploitation of this security vulnerability was known.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-11452?
CVE-2018-11452 is a vulnerability identified in Siemens firmware variants IEC 61850, PROFINET IO, Modbus TCP, and DNP3 TCP for EN100 Ethernet module.
What is the severity of CVE-2018-11452?
The severity of CVE-2018-11452 is high, with a severity value of 7.5.
Which software versions are affected by CVE-2018-11452?
All versions of Siemens firmware variants IEC 61850 for EN100 Ethernet module, PROFINET IO for EN100 Ethernet module, Modbus TCP for EN100 Ethernet module, and DNP3 TCP for EN100 Ethernet module are affected, with versions below 4.33 for IEC 61850.
How can I fix CVE-2018-11452?
To fix CVE-2018-11452, Siemens recommends updating the firmware to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2018-11452?
More information about CVE-2018-11452 can be found in the following references: [Link 1](https://cert-portal.siemens.com/productcert/pdf/ssa-325546.pdf), [Link 2](https://cert-portal.siemens.com/productcert/pdf/ssa-635129.pdf), [Link 3](https://www.securityfocus.com/bid/106221).