Siemens TeleControl Server Basic CVE-2018-4836 Privilege Escalation Vulnerability
BID:102897
CVE-2018-4836 |Info
Siemens TeleControl Server Basic CVE-2018-4836 Privilege Escalation Vulnerability
| Bugtraq ID: | 102897 |
| Class: | Design Error |
| CVE: |
CVE-2018-4836 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 25 2018 12:00AM |
| Updated: | Jan 25 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Siemens TeleControl Server Basic 3.0 SP2 Siemens TeleControl Server Basic 3.0 |
| Not Vulnerable: |
Siemens TeleControl Server Basic 3.1 |
Discussion
Siemens TeleControl Server Basic CVE-2018-4836 Privilege Escalation Vulnerability
Siemens TeleControl Server Basic is prone to a privilege-escalation vulnerability.
An attacker can leverage this issue to escalate privileges and gain administrative access on an affected application.
Versions prior to TeleControl Server Basic 3.1 are vulnerable.
Siemens TeleControl Server Basic is prone to a privilege-escalation vulnerability.
An attacker can leverage this issue to escalate privileges and gain administrative access on an affected application.
Versions prior to TeleControl Server Basic 3.1 are vulnerable.
Exploit / POC
Siemens TeleControl Server Basic CVE-2018-4836 Privilege Escalation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Siemens TeleControl Server Basic CVE-2018-4836 Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Siemens TeleControl Server Basic CVE-2018-4836 Privilege Escalation Vulnerability
References:
References:
- Siemens Homepage (Siemens)
- SSA-651454: Vulnerabilities in TeleControl Server Basic (Siemens)