8.5

CVE-2018-4851

A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device could cause a Denial-of-Service condition by sending certain packets to the device, causing potential reboots of the device. The core functionality of the device could be impacted. The time serving functionality recovers when time synchronization with GPS devices or other NTP servers are completed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Siclock Tc400 Firmware Version -
   Siemens ≫ Siclock Tc400 Version -
Siemens ≫ Siclock Tc100 Firmware Version -
   Siemens ≫ Siclock Tc100 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.46% 0.7
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.2 3.9 4.2
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
NIST 8.5 10 7.8
AV:N/AC:L/Au:N/C:N/I:P/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.securityfocus.com/bid/104672
Third Party Advisory
VDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-197012.pdf
Vendor Advisory
Mitigation