Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2018-4850

Quick assessment

Affected
Siemens AG SIMATIC S7-400 (incl. F) CPU hardware version 4.0 and below, SIMATIC S7-400 (incl. F) CPU hardware version 5.0, SIMATIC S7-400H CPU hardware version 4.5 and below
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Siemens SIMATIC S7-400和SIMATIC S7-400H都是德国西门子(Siemens)公司的用于制造和过程自动化领域的可编程逻辑控制器产品。 Siemens SIMATIC S7-400 (incl. F)和SIMATIC S7-400H CPU硬件中存在安全漏洞,该漏洞源于程序没有正确的验证S7通信数据包。攻击者可利用该漏洞造成拒绝服务。以下产品和版本受到影响:Siemens SIMATIC S7-400 4.0及之前版本,使用5.2之前版本固件的SIMATIC S7-400 (i

AI Predicted 7.5 Difficulty: Easy EPSS 2.42% · P84
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2018-4850

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability has been identified in SIMATIC S7-400 (incl. F) CPU hardware version 4.0 and below (All versions), SIMATIC S7-400 (incl. F) CPU hardware version 5.0 (All firmware versions < V5.2), SIMATIC S7-400H CPU hardware version 4.5 and below (All versions). The affected CPUs improperly validate S7 communication packets which could cause a Denial-of-Service condition of the CPU. The CPU will remain in DEFECT mode until manual restart.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Siemens SIMATIC S7-400和SIMATIC S7-400H 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Siemens SIMATIC S7-400和SIMATIC S7-400H都是德国西门子(Siemens)公司的用于制造和过程自动化领域的可编程逻辑控制器产品。 Siemens SIMATIC S7-400 (incl. F)和SIMATIC S7-400H CPU硬件中存在安全漏洞,该漏洞源于程序没有正确的验证S7通信数据包。攻击者可利用该漏洞造成拒绝服务。以下产品和版本受到影响:Siemens SIMATIC S7-400 4.0及之前版本,使用5.2之前版本固件的SIMATIC S7-400 (i
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Siemens AG SIMATIC S7-400 (incl. F) CPU hardware version 4.0 and below, SIMATIC S7-400 (incl. F) CPU hardware version 5.0, SIMATIC S7-400H CPU hardware version 4.5 and below SIMATIC S7-400 (incl. F) CPU hardware version 4.0 and below : All versions -

II. Public POCs for CVE-2018-4850

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-4850

请登录查看更多情报信息。

Vendor Advisories for CVE-2018-4850 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2018-4850

No comments yet


Leave a comment