mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-07-29 05:56:59 +00:00
547 lines
28 KiB
JSON
547 lines
28 KiB
JSON
{
|
|
"data_version": "4.0",
|
|
"data_type": "CVE",
|
|
"data_format": "MITRE",
|
|
"CVE_data_meta": {
|
|
"ID": "CVE-2018-4834",
|
|
"ASSIGNER": "productcert@siemens.com",
|
|
"STATE": "PUBLIC"
|
|
},
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "A vulnerability has been identified in Desigo PXC00-E.D V4.10 (All versions < V4.10.111), Desigo PXC00-E.D V5.00 (All versions < V5.0.171), Desigo PXC00-E.D V5.10 (All versions < V5.10.69), Desigo PXC00-E.D V6.00 (All versions < V6.0.204), Desigo PXC00/64/128-U V4.10 (All versions < V4.10.111 only with web module), Desigo PXC00/64/128-U V5.00 (All versions < V5.0.171 only with web module), Desigo PXC00/64/128-U V5.10 (All versions < V5.10.69 only with web module), Desigo PXC00/64/128-U V6.00 (All versions < V6.0.204 only with web module), Desigo PXC001-E.D V4.10 (All versions < V4.10.111), Desigo PXC001-E.D V5.00 (All versions < V5.0.171), Desigo PXC001-E.D V5.10 (All versions < V5.10.69), Desigo PXC001-E.D V6.00 (All versions < V6.0.204), Desigo PXC100-E.D V4.10 (All versions < V4.10.111), Desigo PXC100-E.D V5.00 (All versions < V5.0.171), Desigo PXC100-E.D V5.10 (All versions < V5.10.69), Desigo PXC100-E.D V6.00 (All versions < V6.0.204), Desigo PXC12-E.D V4.10 (All versions < V4.10.111), Desigo PXC12-E.D V5.00 (All versions < V5.0.171), Desigo PXC12-E.D V5.10 (All versions < V5.10.69), Desigo PXC12-E.D V6.00 (All versions < V6.0.204), Desigo PXC200-E.D V4.10 (All versions < V4.10.111), Desigo PXC200-E.D V5.00 (All versions < V5.0.171), Desigo PXC200-E.D V5.10 (All versions < V5.10.69), Desigo PXC200-E.D V6.00 (All versions < V6.0.204), Desigo PXC22-E.D V4.10 (All versions < V4.10.111), Desigo PXC22-E.D V5.00 (All versions < V5.0.171), Desigo PXC22-E.D V5.10 (All versions < V5.10.69), Desigo PXC22-E.D V6.00 (All versions < V6.0.204), Desigo PXC22.1-E.D V4.10 (All versions < V4.10.111), Desigo PXC22.1-E.D V5.00 (All versions < V5.0.171), Desigo PXC22.1-E.D V5.10 (All versions < V5.10.69), Desigo PXC22.1-E.D V6.00 (All versions < V6.0.204), Desigo PXC36.1-E.D V4.10 (All versions < V4.10.111), Desigo PXC36.1-E.D V5.00 (All versions < V5.0.171), Desigo PXC36.1-E.D V5.10 (All versions < V5.10.69), Desigo PXC36.1-E.D V6.00 (All versions < V6.0.204), Desigo PXC50-E.D V4.10 (All versions < V4.10.111), Desigo PXC50-E.D V5.00 (All versions < V5.0.171), Desigo PXC50-E.D V5.10 (All versions < V5.10.69), Desigo PXC50-E.D V6.00 (All versions < V6.0.204), Desigo PXM20-E V4.10 (All versions < V4.10.111), Desigo PXM20-E V5.00 (All versions < V5.0.171), Desigo PXM20-E V5.10 (All versions < V5.10.69), Desigo PXM20-E V6.00 (All versions < V6.0.204). A remote attacker with network access to the device could potentially upload a new firmware image to the devices without prior authentication."
|
|
}
|
|
]
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "CWE-306: Missing Authentication for Critical Function",
|
|
"cweId": "CWE-306"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"vendor_name": "Siemens",
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"product_name": "Desigo PXC00-E.D V4.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V4.10.111"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC00-E.D V5.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.0.171"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC00-E.D V5.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.10.69"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC00-E.D V6.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V6.0.204"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC00/64/128-U V4.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V4.10.111 only with web module"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC00/64/128-U V5.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.0.171 only with web module"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC00/64/128-U V5.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.10.69 only with web module"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC00/64/128-U V6.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V6.0.204 only with web module"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC001-E.D V4.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V4.10.111"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC001-E.D V5.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.0.171"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC001-E.D V5.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.10.69"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC001-E.D V6.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V6.0.204"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC100-E.D V4.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V4.10.111"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC100-E.D V5.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.0.171"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC100-E.D V5.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.10.69"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC100-E.D V6.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V6.0.204"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC12-E.D V4.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V4.10.111"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC12-E.D V5.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.0.171"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC12-E.D V5.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.10.69"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC12-E.D V6.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V6.0.204"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC200-E.D V4.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V4.10.111"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC200-E.D V5.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.0.171"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC200-E.D V5.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.10.69"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC200-E.D V6.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V6.0.204"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC22-E.D V4.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V4.10.111"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC22-E.D V5.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.0.171"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC22-E.D V5.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.10.69"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC22-E.D V6.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V6.0.204"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC22.1-E.D V4.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V4.10.111"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC22.1-E.D V5.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.0.171"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC22.1-E.D V5.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.10.69"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC22.1-E.D V6.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V6.0.204"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC36.1-E.D V4.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V4.10.111"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC36.1-E.D V5.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.0.171"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC36.1-E.D V5.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.10.69"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC36.1-E.D V6.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V6.0.204"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC50-E.D V4.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V4.10.111"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC50-E.D V5.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.0.171"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC50-E.D V5.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.10.69"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXC50-E.D V6.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V6.0.204"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXM20-E V4.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V4.10.111"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXM20-E V5.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.0.171"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXM20-E V5.10",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V5.10.69"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Desigo PXM20-E V6.00",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All versions < V6.0.204"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-824231.pdf",
|
|
"refsource": "MISC",
|
|
"name": "https://cert-portal.siemens.com/productcert/pdf/ssa-824231.pdf"
|
|
}
|
|
]
|
|
},
|
|
"impact": {
|
|
"cvss": [
|
|
{
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C",
|
|
"baseScore": 9.8,
|
|
"baseSeverity": "CRITICAL"
|
|
}
|
|
]
|
|
}
|
|
} |