CVE-2018-4839 Details
Description
A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions), Other SIPROTEC 4 relays (All versions), Other SIPROTEC Compact relays (All versions), SIPROTEC 4 7SD80 (All versions < V4.70), SIPROTEC 4 7SJ61 (All versions < V4.96), SIPROTEC 4 7SJ62 (All versions < V4.96), SIPROTEC 4 7SJ64 (All versions < V4.96), SIPROTEC 4 7SJ66 (All versions < V4.30), SIPROTEC Compact 7SJ80 (All versions < V4.77), SIPROTEC Compact 7SK80 (All versions < V4.77). An attacker with local access to the engineering system or in a privileged network position and able to obtain certain network traffic could possibly reconstruct access authorization passwords.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-203306.pdf | CVE | PatchVendor Advisory |
| https://ics-cert.us-cert.gov/advisories/ICSA-18-067-01 | [email protected] | Third Party AdvisoryUS Government Resource |
| https://cert-portal.siemens.com/productcert/pdf/ssa-203306.pdf | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-326 | Inadequate Encryption Strength | [email protected] |
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| siemens siprotec compact 7sj80 firmware | < 4.77 |
CPE
Remediation
| |
| siemens siprotec compact 7sj80 | All versions |
CPE
Remediation
| |
| siemens siprotec compact 7sk80 firmware | < 4.77 |
CPE
Remediation
| |
| siemens siprotec compact 7sk80 | All versions |
CPE
Remediation
| |
| siemens siprotec 4 7sj66 firmware | < 4.30 |
CPE
Remediation
| |
| siemens siprotec 4 7sj66 | All versions |
CPE
Remediation
| |
| siemens digsi 4 | < 4.92 |
CPE
Remediation
| |
| siemens en100 ethernet module iec 104 firmware | All versions |
CPE
Remediation
| |
| siemens en100 ethernet module iec 104 | All versions |
CPE
Remediation
| |
| siemens en100 ethernet module dnp3 firmware | All versions |
CPE
Remediation
| |
| siemens en100 ethernet module dnp3 | All versions |
CPE
Remediation
| |
| siemens en100 ethernet module modbus tcp firmware | All versions |
CPE
Remediation
| |
| siemens en100 ethernet module modbus tcp | All versions |
CPE
Remediation
| |
| siemens en100 ethernet module profinet io firmware | All versions |
CPE
Remediation
| |
| siemens en100 ethernet module profinet io | All versions |
CPE
Remediation
| |
| siemens en100 ethernet module iec 61850 firmware | < 4.30 |
CPE
Remediation
| |
| siemens en100 ethernet module iec 61850 | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jul 13, 2021 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Mar 29, 2018 | Initial Analysis | [email protected] |