CVE-2018-11454
published 2018-08-07CVE-2018-11454: A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC…
PriorityP339high8.6CVSS 3.0
AVLACLPRNUIRSCCHIHAH
EPSS
0.44%
35.7th percentile
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 6), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V15 (All versions < V15 Update 2). Improper file permissions in the default installation of TIA Portal may allow an attacker with local file system access to manipulate resources which may be transferred to devices and executed there by a different user. No special privileges are required, but the victim needs to transfer the manipulated files to a device. Execution is caused on the target device rather than on the PG device.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_step_7 | — | — |
| siemens | simatic_step_7 | — | — |
| siemens | simatic_step_7 | — | — |
| siemens | simatic_step_7 | — | — |
| siemens | simatic_step_7 | — | — |
| siemens | simatic_step_7 | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC STEP 7 and SIMATIC WinCC (Update A)
cisa_ics·2018-08-14
Siemens SIMATIC STEP 7 and SIMATIC WinCC (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC STEP 7 and SIMATIC WinCC (Update A)
Last RevisedOctober 09, 2018
Alert CodeICSA-18-226-01
## 1. EXECUTIVE SUMMARY
-
CVSS v3 8.6
- ATTENTION: Exploitable locally/low skill level to exploit
- Vendor: Siemens
- Equipment: SIMATIC STEP 7 (TIA Portal) and SIMATIC WinCC (TIA Portal)
- Vulnerabilities: Incorrect Default Permissions
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-18-226-01 Siemens SIMATIC STEP 7 and SIMATIC WinCC that was published August 14, 2018, on the NCCIC/ICS-CERT website.
## 3. RISK EVALUAT
GHSA
GHSA-9qvc-rfh7-2xv6: A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) an
ghsa_unreviewed·2022-05-13
CVE-2018-11454 [HIGH] CWE-732 GHSA-9qvc-rfh7-2xv6: A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) an
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 6), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V15 (All versions < V15 Update 2). Improper file permissions in the default installation of TIA Portal may allow an attacker with local file system access to manipulate resources which may be transferred to devices and executed there by a different user. No special privileges are required, but the victim needs to transfer the manipulated files to a device. Execution is caused on the target device rather than on the PG device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-08-07
Published