First published: Tue Aug 07 2018(Updated: )
A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4). An attacker with network access to the device could send specially crafted network packets to determine whether or not a network port on another remote system is accessible or not. This allows the attacker to do basic network scanning using the victims machine. Successful exploitation requires a network connection to the affected device. The attacker does not need privileges, no user interaction is required. The impact is limited to determining whether or not a port on a target system is accessible by the affected device.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Automation License Manager | <5.3.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-11456 is medium.
CVE-2018-11456 affects all versions of Automation License Manager prior to 5.3.4.4.
CVE-2018-11456 allows an attacker with network access to determine the accessibility of a network port on a remote system.
To mitigate CVE-2018-11456, update Automation License Manager to version 5.3.4.4 or later.
More information about CVE-2018-11456 can be found at http://www.securityfocus.com/bid/105114 and https://cert-portal.siemens.com/productcert/pdf/ssa-920962.pdf.