PT-2018-1120 · Siemens · Tim 1531 Irc

CVE-2018-4841

·

Publicado

2018-03-27

·

Atualizado

2023-03-24

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TIM 1531 IRC versions prior to V1.1
Description A remote attacker with network access to port 80/tcp or port 443/tcp could perform administrative operations on the device without prior authentication. Successful exploitation could allow causing a denial-of-service, or reading and manipulating data as well as configuration settings of the affected device. The issue is related to the incorrect implementation of the authentication algorithm. At the stage of publishing this security advisory, no public exploitation is known.
Recommendations For versions prior to V1.1, Siemens provides mitigations to resolve the issue. As a temporary workaround, consider restricting access to ports 80/tcp and 443/tcp until a patch is available.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00541
CVE-2018-4841

Produtos afetados

Tim 1531 Irc