CVE-2018-4840: High severity siemens siprotec compact 7sj80 vulnerability
A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions). The device engineering mechanism allows an unauthenticated remote user to upload a modified device configuration overwriting access authorization passwords.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-4840?
The severity of CVE-2018-4840 is high with a severity value of 7.5.
What software versions are affected by CVE-2018-4840?
DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.30), and EN100 Ethernet module Modbus TCP variant (All versions) are affected by CVE-2018-4840.
How can I fix CVE-2018-4840?
Apply the necessary updates and patches provided by Siemens to mitigate the vulnerability.
Where can I find more information about CVE-2018-4840?
You can find more information about CVE-2018-4840 in the Siemens ProductCERT advisory (https://cert-portal.siemens.com/productcert/pdf/ssa-203306.pdf) and the ICS-CERT advisory (https://ics-cert.us-cert.gov/advisories/ICSA-18-067-01).
What is the Common Weakness Enumeration (CWE) ID of CVE-2018-4840?
The CWE ID of CVE-2018-4840 is CWE-306.