6.5

CVE-2018-4855

A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). Unencrypted storage of passwords in the client configuration files and during network transmission could allow an attacker in a privileged position to obtain access passwords.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Siclock Tc400 Firmware Version -
   Siemens ≫ Siclock Tc400 Version -
Siemens ≫ Siclock Tc100 Firmware Version -
   Siemens ≫ Siclock Tc100 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.02% 0.59
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-311 Missing Encryption of Sensitive Data

The product does not encrypt sensitive or critical information before storage or transmission.

http://www.securityfocus.com/bid/104672
Third Party Advisory
VDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-197012.pdf
Vendor Advisory
Mitigation