SB2018081512 - Multiple vulnerabilities in Siemens Automation License Manager
Published: August 15, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Relative path traversal (CVE-ID: CVE-2018-11455)
The vulnerability allows a remote attacker to conduct directory traversal attack on the target system.
The vulnerability exists due to relative path traversal. A remote unauthenticated attacker can trick the victim into visiting a specially crafted website, move arbitrary files to conduct path traversal attack and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
2) Improper input validation (CVE-ID: CVE-2018-11456)
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote unauthenticated attacker can send specially crafted network packets to determine whether a network port on another remote system is accessible and do basic network scanning using the victim’s machine.
Remediation
Install update from vendor's website.