CVE-2018-4858
https://notcve.org/view.php?id=CVE-2018-4858
A vulnerability has been identified in IEC 61850 system configurator (All versions < V5.80), DIGSI 5 (affected as IEC 61850 system configurator is incorporated) (All versions < V7.80), DIGSI 4 (All versions < V4.93), SICAM PAS/PQS (All versions < V8.11), SICAM PQ Analyzer (All versions < V3.11), SICAM SCC (All versions < V9.02 HF3). A service of the affected products listening on all of the host's network interfaces on either port 4884/TCP, 5885/TCP, or port 5886/TCP could allow an attacker to either exfiltrate limited data from the system or to execute code with Microsoft Windows user permissions. Successful exploitation requires an attacker to be able to send a specially crafted network request to the vulnerable service and a user interacting with the service's client application on the host. In order to execute arbitrary code with Microsoft Windows user permissions, an attacker must be able to plant the code in advance on the host by other means. The vulnerability has limited impact to confidentiality and integrity of the affected system. • http://www.securityfocus.com/bid/105933 https://cert-portal.siemens.com/productcert/pdf/ssa-159860.pdf https://ics-cert.us-cert.gov/advisories/ICSA-18-317-01 • CWE-284: Improper Access Control •
CVE-2016-8566
https://notcve.org/view.php?id=CVE-2016-8566
An issue was discovered in Siemens SICAM PAS before 8.00. Because of Storing Passwords in a Recoverable Format, an authenticated local attacker with certain privileges could possibly reconstruct the passwords of users for accessing the database. Ha sido descubierto un problema en Siemens SICAM PAS en versiones anteriores a 8.00. Por conservar contraseñas en un formato recuperable, un atacante local autenticado con determinados privilegios puede posiblemente reconstruir las contraseñas de usuarios para acceder a la base de datos. • http://www.securityfocus.com/bid/94552 https://ics-cert.us-cert.gov/advisories/ICSA-16-336-01 • CWE-255: Credentials Management Errors •
CVE-2016-8567
https://notcve.org/view.php?id=CVE-2016-8567
An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded passwords is present in the SICAM PAS installations. Attackers might gain privileged access to the database over Port 2638/TCP. Ha sido descubierto un problema en Siemens SICAM PAS en versiones anteriores a 8.00. Una cuenta de fábrica con contraseñas embebidas está presente en las instalaciones de SICAM PAS. • http://www.securityfocus.com/bid/94549 https://ics-cert.us-cert.gov/advisories/ICSA-16-336-01 • CWE-798: Use of Hard-coded Credentials •
CVE-2016-9157
https://notcve.org/view.php?id=CVE-2016-9157
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially lead to unauthenticated remote code execution by sending specially crafted packets to port 19234/TCP. Una vulnerabilidad en SICAM PAS (todas las versiones anteriores a 8.09) de Siemens, podría permitir a un atacante remoto causar una condición de Denegación de Servicio y conllevar potencialmente a la ejecución de código remota no autenticada mediante el envío de paquetes diseñados al puerto 19234/TCP. • http://www.securityfocus.com/bid/94549 http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-946325.pdf • CWE-20: Improper Input Validation CWE-284: Improper Access Control •
CVE-2016-9156
https://notcve.org/view.php?id=CVE-2016-9156
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to upload, download, or delete files in certain parts of the file system by sending specially crafted packets to port 19235/TCP. Una vulnerabilidad en SICAM PAS (todas las versiones anteriores a V8.09) de Siemens, podría permitir a un atacante remoto cargar, descargar o eliminar archivos en ciertas partes del sistema de archivos mediante el envío de paquetes especialmente diseñados al puerto 19235/TCP. • http://www.securityfocus.com/bid/94549 http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-946325.pdf • CWE-20: Improper Input Validation CWE-284: Improper Access Control •