Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2018-4833

8.8 · HIGH
Published Jun 14, 2018 siemens CWE-122 EPSS 0.95% (59th pctl)

Overview

CVE-2018-4833 is a high-severity vulnerability affecting siemens rfid_181-eip_firmware. It was published on June 14, 2018 and has a CVSS 3.0 base score of 8.8 (HIGH).

This vulnerability has a CVSS 3.0 base score of 8.8, rated HIGH. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

Technical Description

A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.6), SCALANCE X-300 switch family (incl. SIPLUS NET variants) (All versions < V4.1.3), SCALANCE X408 (All versions < V4.1.3), SCALANCE X414 (All versions), SIMATIC RF182C (All versions). Unprivileged remote attackers located in the same local network segment (OSI Layer 2) could gain remote code execution on the affected products by sending a specially crafted DHCP response to a client's DHCP request.

Remediation

Check the references section for vendor advisories and patches from siemens. Update rfid_181-eip_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
siemens scalance_x200_firmware >= 0, < 5.2.3 Affected
siemens scalance_x200irt_firmware >= 0, < 5.4.1 Affected

Frequently Asked Questions

What is CVE-2018-4833?

CVE-2018-4833 is a high-severity vulnerability affecting siemens rfid_181-eip_firmware. It was published on June 14, 2018 and has a CVSS 3.0 base score of 8.8 (HIGH).

How severe is CVE-2018-4833?

This vulnerability has a CVSS 3.0 base score of 8.8, rated HIGH. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2018-4833?

Check the references section for vendor advisories and patches from siemens. Update rfid_181-eip_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2018-4833?

CyberStrike's AI-powered security agents can automatically detect CVE-2018-4833 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.