First published: Tue Jul 03 2018(Updated: )
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). Unencrypted storage of passwords in the client configuration files and during network transmission could allow an attacker in a privileged position to obtain access passwords.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Siclock Tc400 Firmware | ||
Siemens Siclock Tc400 | ||
Siemens Siclock Tc100 Firmware | ||
Siemens Siclock Tc100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-4855 has been classified with high severity due to the potential for attackers to gain unauthorized access to passwords.
CVE-2018-4855 affects all versions of Siemens SICLOCK TC100 and TC400.
To mitigate CVE-2018-4855, ensure to secure configuration files and utilize encrypted transmission for passwords.
CVE-2018-4855 is an unencrypted storage vulnerability impacting the security of password data.
CVE-2018-4855 can potentially be exploited by attackers who have privileged access to the network.