10

CVE-2018-4853

A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp could modify the firmware of the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Siclock Tc400 Firmware Version -
   Siemens ≫ Siclock Tc400 Version -
Siemens ≫ Siclock Tc100 Firmware Version -
   Siemens ≫ Siclock Tc100 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.3% 0.81
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

http://www.securityfocus.com/bid/104672
Third Party Advisory
VDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-197012.pdf
Vendor Advisory
Mitigation