目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2018-11451— Siemens EN100 Ethernet Communication Module和SIPROTEC 5 relays 输入验证漏洞

AI Predicted 5.3 Difficulty: Moderate EPSS 2.39% · P83
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2018-11451の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
N/A
ソース: CVE Program / CVE List V5
脆弱性説明
A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firmware variant PROFINET IO for EN100 Ethernet module (All versions), Firmware variant Modbus TCP for EN100 Ethernet module (All versions), Firmware variant DNP3 TCP for EN100 Ethernet module (All versions), Firmware variant IEC104 for EN100 Ethernet module (All versions < V1.22), SIPROTEC 5 relays with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions < V7.80), SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules (All versions < V7.58). Specially crafted packets to port 102/tcp could cause a denial-of-service condition in the affected products. A manual restart is required to recover the EN100 module functionality of the affected devices. Successful exploitation requires an attacker with network access to send multiple packets to the affected products or modules. As a precondition the IEC 61850-MMS communication needs to be activated on the affected products or modules. No user interaction or privileges are required to exploit the vulnerability. The vulnerability could allow causing a Denial-of-Service condition of the network functionality of the device, compromising the availability of the system. At the time of advisory publication no public exploitation of this security vulnerability was known.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Siemens EN100 Ethernet Communication Module和SIPROTEC 5 relays 输入验证漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Siemens EN100 Ethernet Communication Module和SIPROTEC 5 relays都是德国西门子(Siemens)公司的产品。Siemens EN100 Ethernet Communication Module是一款以太网模块产品。SIPROTEC 5 relays是一款继电器。 Siemens EN100 Ethernet Communication Module和SIPROTEC 5 relays中存在拒绝服务漏洞。攻击者可通过向102/tcp端口发送特制的数
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

II. CVE-2018-11451の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2018-11451のインテリジェンス情報

登录查看更多情报信息。

CVE-2018-11451 厂商安全公告 (3)

IV. 関連脆弱性

V. CVE-2018-11451へのコメント

まだコメントはありません


コメントを残す