Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-13807


A vulnerability has been identified in SCALANCE X300 (All versions < V4.0.0), SCALANCE X408 (All versions < V4.0.0), SCALANCE X414 (All versions). The web interface on port 443/tcp could allow an attacker to cause a Denial-of-Service condition by sending specially crafted packets to the web server. The device will automatically reboot, impacting network availability for other devices. An attacker must have network access to port 443/tcp to exploit the vulnerability. Neither valid credentials nor interaction by a legitimate user is required to exploit the vulnerability. There is no confidentiality or integrity impact, only availability is temporarily impacted. This vulnerability could be triggered by publicly available tools.


Published

2018-09-12T13:29:01.157

Last Modified

2024-11-21T03:48:06.303

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 8.6 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System siemens scalance_x408_firmware < 4.0.0 Yes
Hardware siemens scalance_x408 - No
Operating System siemens scalance_x300_firmware < 4.0.0 Yes
Hardware siemens scalance_x300 - No
Operating System siemens scalance_x414_firmware - Yes
Hardware siemens scalance_x414 - No

References