CVE-2018-4832 Details
Description
A vulnerability has been identified in OpenPCS 7 V7.1 and earlier (All versions), OpenPCS 7 V8.0 (All versions), OpenPCS 7 V8.1 (All versions < V8.1 Upd5), OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd1), SIMATIC BATCH V7.1 and earlier (All versions), SIMATIC BATCH V8.0 (All versions < V8.0 SP1 Upd21), SIMATIC BATCH V8.1 (All versions < V8.1 SP1 Upd16), SIMATIC BATCH V8.2 (All versions < V8.2 Upd10), SIMATIC BATCH V9.0 (All versions < V9.0 SP1), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions < 15 SP1), SIMATIC PCS 7 V7.1 and earlier (All versions), SIMATIC PCS 7 V8.0 (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP1), SIMATIC Route Control V7.1 and earlier (All versions), SIMATIC Route Control V8.0 (All versions), SIMATIC Route Control V8.1 (All versions), SIMATIC Route Control V8.2 (All versions), SIMATIC Route Control V9.0 (All versions < V9.0 Upd1), SIMATIC WinCC Runtime Professional V13 (All versions < V13 SP2 Upd2), SIMATIC WinCC Runtime Professional V14 (All versions < V14 SP1 Upd5), SIMATIC WinCC V7.2 and earlier (All versions < WinCC 7.2 Upd 15), SIMATIC WinCC V7.3 (All versions < WinCC 7.3 Upd 16), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Upd 4), SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). Specially crafted messages sent to the RPC service of the affected products could cause a Denial-of-Service condition on the remote and local communication functionality of the affected products. A reboot of the system is required to recover the remote and local communication functionality. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://packetstormsecurity.com/files/155665/Siemens-Security-Advisory-SPPA-T3000-Code-Execution.html | CVE | Third Party AdvisoryVDB Entry |
| https://cert-portal.siemens.com/productcert/pdf/ssa-348629.pdf | CVE | MitigationVendor Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-451445.pdf | CVE | Vendor Advisory |
| http://packetstormsecurity.com/files/155665/Siemens-Security-Advisory-SPPA-T3000-Code-Execution.html | [email protected] | Third Party AdvisoryVDB Entry |
| https://cert-portal.siemens.com/productcert/pdf/ssa-348629.pdf | [email protected] | MitigationVendor Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-451445.pdf | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| siemens openpcs 7 | <= 7.1 8.0 8.1 - 8.1 upd_1 8.1 upd_2 8.1 upd_3 8.1 upd_4 8.2 9.0 |
CPE
Remediation
| |
| siemens simatic batch | 7.1 8.0 - 8.0 sp1_upd20 8.1 - 8.1 sp1_upd14 8.1 sp1_upd15 8.2 - 8.2 upd_9 9.0 |
CPE
Remediation
| |
| siemens simatic net pc | < 15 15 - |
CPE
Remediation
| |
| siemens simatic pcs 7 | <= 7.1 8.0 8.1 8.2 - 9.0 - |
CPE
Remediation
| |
| siemens simatic route control | <= 7.1 8.0 8.1 9.0 - |
CPE
Remediation
| |
| siemens simatic wincc runtime professional | < 13 13 - 13 sp2_upd_1 14 - 14 sp1_upd_4 |
CPE
Remediation
| |
| siemens simatic wincc | < 7.2 7.2 - 7.2 upd_14 7.3 - 7.3 upd_15 7.4 - 7.4 sp1 7.4 sp1_upd_3 |
CPE
Remediation
| |
| siemens sppa-t3000 application server | < r8.2 r8.2 - r8.2 sp1 |
CPE
Remediation
| |
| siemens simatic net pc software | < 14.0 |
CPE
Remediation
| |
Change History
17 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 6, 2022 | Modified Analysis | [email protected] |
| Apr 12, 2022 | CVE Modified | [email protected] |
| Apr 12, 2022 | CVE Modified | [email protected] |
| Feb 24, 2022 | CVE Modified | [email protected] |
| Feb 22, 2022 | CVE Modified | [email protected] |
| Mar 10, 2020 | CVE Modified | [email protected] |
| Dec 13, 2019 | CVE Modified | [email protected] |
| Dec 12, 2019 | CVE Modified | [email protected] |
| Dec 12, 2019 | CVE Modified | [email protected] |
| Dec 10, 2019 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Oct 10, 2018 | CVE Modified | [email protected] |
| Jun 13, 2018 | Initial Analysis | [email protected] |
| Apr 26, 2018 | CVE Modified | [email protected] |