Vulnerability Name: CVE-2018-13814 (CCN-152928) Assigned: 2018-11-13 Published: 2018-11-13 Updated: 2019-10-09 Summary: A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V14), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V14), SIMATIC WinCC Runtime Advanced (All versions < V14), SIMATIC WinCC Runtime Professional (All versions < V14), SIMATIC WinCC (TIA Portal) (All versions < V14), SIMATIC HMI Classic Devices (TP/MP/OP/MP Mobile Panel) (All versions). The integrated web server (port 80/tcp and port 443/tcp) of the affected devices could allow an attacker to inject HTTP headers. An attacker must trick a valid user who is authenticated to the device into clicking on a malicious link to exploit the vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known. CVSS v3 Severity: 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H )7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N )3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-20 Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2018-13814 Source: BID Type: Third Party Advisory, VDB Entry105931 Source: CCN Type: Siemens Security Advisory SSA-944083HTTP Header Injection in SIMATIC Panels and SIMATIC WinCC (TIA Portal) Source: CONFIRM Type: Vendor Advisoryhttps://cert-portal.siemens.com/productcert/pdf/ssa-944083.pdf Source: XF Type: UNKNOWNsiemens-cve201813814-header-injection(152928) Source: CCN Type: ICSA-18-317-03Siemens SIMATIC Panels and SIMATIC WinCC (TIA Portal) Vulnerable Configuration: Configuration 1 :cpe:/o:siemens:simatic_hmi_comfort_panels_firmware:*:*:*:*:*:*:*:* (Version < 14.0)AND cpe:/h:siemens:simatic_hmi_comfort_panels:-:*:*:*:*:*:*:* Configuration 2 :cpe:/o:siemens:simatic_hmi_comfort_outdoor_panels_firmware:*:*:*:*:*:*:*:* (Version < 14.0)AND cpe:/h:siemens:simatic_hmi_comfort_outdoor_panels:-:*:*:*:*:*:*:* Configuration 3 :cpe:/o:siemens:simatic_hmi_ktp_mobile_panels_ktp400f_firmware:*:*:*:*:*:*:*:* (Version < 14.0)AND cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp400f:-:*:*:*:*:*:*:* Configuration 4 :cpe:/o:siemens:simatic_hmi_ktp_mobile_panels_ktp700_firmware:*:*:*:*:*:*:*:* (Version < 14.0)AND cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp700:-:*:*:*:*:*:*:* Configuration 5 :cpe:/o:siemens:simatic_hmi_ktp_mobile_panels_ktp700f_firmware:*:*:*:*:*:*:*:* (Version < 14.0)AND cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp700f:-:*:*:*:*:*:*:* Configuration 6 :cpe:/o:siemens:simatic_hmi_ktp_mobile_panels_ktp900_firmware:*:*:*:*:*:*:*:* (Version < 14.0)AND cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp900:-:*:*:*:*:*:*:* Configuration 7 :cpe:/o:siemens:simatic_hmi_ktp_mobile_panels_ktp900f_firmware:*:*:*:*:*:*:*:* (Version < 14.0)AND cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp900f:-:*:*:*:*:*:*:* Configuration 8 :cpe:/a:siemens:simatic_wincc_(tia_portal):*:*:*:*:*:*:*:* (Version < 14.0)OR cpe:/a:siemens:simatic_wincc_runtime:*:*:*:*:advanced:*:*:* (Version < 14.0) OR cpe:/a:siemens:simatic_wincc_runtime:*:*:*:*:professional:*:*:* (Version < 14.0) Configuration 9 :cpe:/o:siemens:simatic_hmi_tp_firmware:*:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_hmi_tp:-:*:*:*:*:*:*:* Configuration 10 :cpe:/o:siemens:simatic_hmi_mp_firmware:*:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_hmi_mp:-:*:*:*:*:*:*:* Configuration 11 :cpe:/o:siemens:simatic_hmi_op_firmware:*:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_hmi_op:-:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:siemens:simatic_wincc_runtime:*:*:*:*:advanced:*:*:* OR cpe:/a:siemens:simatic_wincc_runtime:*:*:*:*:professional:*:*:* OR cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp400f:-:*:*:*:*:*:*:* OR cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp700:-:*:*:*:*:*:*:* OR cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp700f:-:*:*:*:*:*:*:* OR cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp900:-:*:*:*:*:*:*:* OR cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp900f:-:*:*:*:*:*:*:* OR cpe:/a:siemens:simatic_wincc_(tia_portal):*:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
siemens simatic hmi comfort panels firmware *
siemens simatic hmi comfort panels -
siemens simatic hmi comfort outdoor panels firmware *
siemens simatic hmi comfort outdoor panels -
siemens simatic hmi ktp mobile panels ktp400f firmware *
siemens simatic hmi ktp mobile panels ktp400f -
siemens simatic hmi ktp mobile panels ktp700 firmware *
siemens simatic hmi ktp mobile panels ktp700 -
siemens simatic hmi ktp mobile panels ktp700f firmware *
siemens simatic hmi ktp mobile panels ktp700f -
siemens simatic hmi ktp mobile panels ktp900 firmware *
siemens simatic hmi ktp mobile panels ktp900 -
siemens simatic hmi ktp mobile panels ktp900f firmware *
siemens simatic hmi ktp mobile panels ktp900f -
siemens simatic wincc (tia portal) *
siemens simatic wincc runtime *
siemens simatic wincc runtime *
siemens simatic hmi tp firmware *
siemens simatic hmi tp -
siemens simatic hmi mp firmware *
siemens simatic hmi mp -
siemens simatic hmi op firmware *
siemens simatic hmi op -
siemens simatic wincc runtime *
siemens simatic wincc runtime *
siemens simatic hmi ktp mobile panels ktp400f -
siemens simatic hmi ktp mobile panels ktp700 -
siemens simatic hmi ktp mobile panels ktp700f -
siemens simatic hmi ktp mobile panels ktp900 -
siemens simatic hmi ktp mobile panels ktp900f -
siemens simatic wincc (tia portal) *