Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-13813

EPSS 0.26% · P49
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2018-13813

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15 Update 4), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15 Update 4), SIMATIC WinCC Runtime Advanced (All versions < V15 Update 4), SIMATIC WinCC Runtime Professional (All versions < V15 Update 4), SIMATIC WinCC (TIA Portal) (All versions < V15 Update 4), SIMATIC HMI Classic Devices (TP/MP/OP/MP Mobile Panel) (All versions). The webserver of affected HMI devices may allow URL redirections to untrusted websites. An attacker must trick a valid user who is authenticated to the device into clicking on a malicious link to exploit the vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
指向未可信站点的URL重定向(开放重定向)
Source: NVD (National Vulnerability Database)
Vulnerability Title
多款Siemens产品安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Siemens SIMATIC HMI Comfort Panels等都是德国西门子(Siemens)公司的用于操控和监控机器和设备的HMI软件。 多款Siemens产品中的webserver存在开放重定向漏洞。攻击者可借助恶意的链接利用该漏洞将用户重定向到不可信的网站。以下产品和版本受到影响:Siemens SIMATIC HMI Comfort Panels 4”-22” 15 Update 4之前版本;SIMATIC HMI Comfort Outdoor Panels 7” & 15” 15 Up
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

II. Public POCs for CVE-2018-13813

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-13813

登录查看更多情报信息。

Same Patch Batch · Siemens AG · 2018-12-13 · 7 CVEs total

CVE-2018-13804Siemens SIMATIC IT LMS、SIMATIC IT Production Suite和SIMATIC IT UA Discrete Manufacturing 授权
CVE-2018-13811Siemens SIMATIC STEP 7 安全漏洞
CVE-2018-13812多款Siemens产品路径遍历漏洞
CVE-2018-13814Siemens SIMATIC Panels和SIMATIC WinCC 代码注入漏洞
CVE-2018-13815Siemens SIMATIC S7-1200和SIMATIC S7-1500 安全漏洞
CVE-2018-16555多款Siemens产品跨站脚本漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2018-13813

No comments yet


Leave a comment