CVE-2018-4856
MEDIUMSICLOCK TC100 and TC400 Firmware - Authenticated Denial of Service via User Lockout
Title source: llmDescription
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with administrative access to the device's management interface could lock out legitimate users. Manual interaction is required to restore the access of legitimate users.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/104672
Mitigation, Vendor Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-197012.pdf
Scores
CVSS v3
4.9
EPSS
0.0023
EPSS Percentile
46.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-287
Status
published
Products (2)
siemens/siclock_tc100_firmware
siemens/siclock_tc400_firmware
Published
Jul 03, 2018
Tracked Since
Feb 18, 2026