CVE-2018-4852

CRITICAL

SICLOCK TC100 and TC400 - Authentication Bypass via Device-Specific Knowledge

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device could potentially circumvent the authentication mechanism if he/she is able to obtain certain knowledge specific to the attacked device.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104672
Mitigation, Vendor Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-197012.pdf

Scores

CVSS v3 9.8
EPSS 0.0161
EPSS Percentile 82.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287 CWE-288
Status published
Products (2)
siemens/siclock_tc100_firmware
siemens/siclock_tc400_firmware
Published Jul 03, 2018
Tracked Since Feb 18, 2026