SB2018081512 - Multiple vulnerabilities in Siemens Automation License Manager 



SB2018081512 - Multiple vulnerabilities in Siemens Automation License Manager

Published: August 15, 2018

Security Bulletin ID SB2018081512
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Relative path traversal (CVE-ID: CVE-2018-11455)

The vulnerability allows a remote attacker to conduct directory traversal attack on the target system.

The vulnerability exists due to relative path traversal. A remote unauthenticated attacker can trick the victim into visiting a specially crafted website, move arbitrary files to conduct path traversal attack and execute arbitrary code with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


2) Improper input validation (CVE-ID: CVE-2018-11456)

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The vulnerability exists due to insufficient validation of user-supplied input. A remote unauthenticated attacker can send specially crafted network packets to determine whether a network port on another remote system is accessible and do basic network scanning using the victim’s machine.


Remediation

Install update from vendor's website.