SIMATIC WinCC OA UI CVE-2018-4844 Access Bypass Vulnerability
BID:103475
CVE-2018-4844 |Info
SIMATIC WinCC OA UI CVE-2018-4844 Access Bypass Vulnerability
| Bugtraq ID: | 103475 |
| Class: | Access Validation Error |
| CVE: |
CVE-2018-4844 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2018 12:00AM |
| Updated: | Mar 20 2018 12:00AM |
| Credit: | Alexander Bolshev from IOActive and Ivan Yushkevich from Embedi |
| Vulnerable: |
Siemens SIMATIC WinCC OA UI 0 |
| Not Vulnerable: |
Siemens SIMATIC WinCC OA UI 3.15.10 |
Discussion
SIMATIC WinCC OA UI CVE-2018-4844 Access Bypass Vulnerability
SIMATIC WinCC OA UI is prone to an access-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks.
Versions prior to SIMATIC WinCC OA UI 3.15.10 are vulnerable.
SIMATIC WinCC OA UI is prone to an access-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks.
Versions prior to SIMATIC WinCC OA UI 3.15.10 are vulnerable.
Exploit / POC
SIMATIC WinCC OA UI CVE-2018-4844 Access Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SIMATIC WinCC OA UI CVE-2018-4844 Access Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SIMATIC WinCC OA UI CVE-2018-4844 Access Bypass Vulnerability
References:
References: