Vulnerability Name:

CVE-2018-13814 (CCN-152928)

Assigned:2018-11-13
Published:2018-11-13
Updated:2019-10-09
Summary:A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V14), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V14), SIMATIC WinCC Runtime Advanced (All versions < V14), SIMATIC WinCC Runtime Professional (All versions < V14), SIMATIC WinCC (TIA Portal) (All versions < V14), SIMATIC HMI Classic Devices (TP/MP/OP/MP Mobile Panel) (All versions). The integrated web server (port 80/tcp and port 443/tcp) of the affected devices could allow an attacker to inject HTTP headers. An attacker must trick a valid user who is authenticated to the device into clicking on a malicious link to exploit the vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-20
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2018-13814

Source: BID
Type: Third Party Advisory, VDB Entry
105931

Source: CCN
Type: Siemens Security Advisory SSA-944083
HTTP Header Injection in SIMATIC Panels and SIMATIC WinCC (TIA Portal)

Source: CONFIRM
Type: Vendor Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-944083.pdf

Source: XF
Type: UNKNOWN
siemens-cve201813814-header-injection(152928)

Source: CCN
Type: ICSA-18-317-03
Siemens SIMATIC Panels and SIMATIC WinCC (TIA Portal)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:siemens:simatic_hmi_comfort_panels_firmware:*:*:*:*:*:*:*:* (Version < 14.0)
  • AND
  • cpe:/h:siemens:simatic_hmi_comfort_panels:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:siemens:simatic_hmi_comfort_outdoor_panels_firmware:*:*:*:*:*:*:*:* (Version < 14.0)
  • AND
  • cpe:/h:siemens:simatic_hmi_comfort_outdoor_panels:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:siemens:simatic_hmi_ktp_mobile_panels_ktp400f_firmware:*:*:*:*:*:*:*:* (Version < 14.0)
  • AND
  • cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp400f:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:siemens:simatic_hmi_ktp_mobile_panels_ktp700_firmware:*:*:*:*:*:*:*:* (Version < 14.0)
  • AND
  • cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp700:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:siemens:simatic_hmi_ktp_mobile_panels_ktp700f_firmware:*:*:*:*:*:*:*:* (Version < 14.0)
  • AND
  • cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp700f:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:siemens:simatic_hmi_ktp_mobile_panels_ktp900_firmware:*:*:*:*:*:*:*:* (Version < 14.0)
  • AND
  • cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp900:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:siemens:simatic_hmi_ktp_mobile_panels_ktp900f_firmware:*:*:*:*:*:*:*:* (Version < 14.0)
  • AND
  • cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp900f:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/a:siemens:simatic_wincc_(tia_portal):*:*:*:*:*:*:*:* (Version < 14.0)
  • OR cpe:/a:siemens:simatic_wincc_runtime:*:*:*:*:advanced:*:*:* (Version < 14.0)
  • OR cpe:/a:siemens:simatic_wincc_runtime:*:*:*:*:professional:*:*:* (Version < 14.0)

  • Configuration 9:
  • cpe:/o:siemens:simatic_hmi_tp_firmware:*:*:*:*:*:*:*:*
  • AND
  • cpe:/h:siemens:simatic_hmi_tp:-:*:*:*:*:*:*:*

  • Configuration 10:
  • cpe:/o:siemens:simatic_hmi_mp_firmware:*:*:*:*:*:*:*:*
  • AND
  • cpe:/h:siemens:simatic_hmi_mp:-:*:*:*:*:*:*:*

  • Configuration 11:
  • cpe:/o:siemens:simatic_hmi_op_firmware:*:*:*:*:*:*:*:*
  • AND
  • cpe:/h:siemens:simatic_hmi_op:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:siemens:simatic_wincc_runtime:*:*:*:*:advanced:*:*:*
  • OR cpe:/a:siemens:simatic_wincc_runtime:*:*:*:*:professional:*:*:*
  • OR cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp400f:-:*:*:*:*:*:*:*
  • OR cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp700:-:*:*:*:*:*:*:*
  • OR cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp700f:-:*:*:*:*:*:*:*
  • OR cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp900:-:*:*:*:*:*:*:*
  • OR cpe:/h:siemens:simatic_hmi_ktp_mobile_panels_ktp900f:-:*:*:*:*:*:*:*
  • OR cpe:/a:siemens:simatic_wincc_(tia_portal):*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    siemens simatic hmi comfort panels firmware *
    siemens simatic hmi comfort panels -
    siemens simatic hmi comfort outdoor panels firmware *
    siemens simatic hmi comfort outdoor panels -
    siemens simatic hmi ktp mobile panels ktp400f firmware *
    siemens simatic hmi ktp mobile panels ktp400f -
    siemens simatic hmi ktp mobile panels ktp700 firmware *
    siemens simatic hmi ktp mobile panels ktp700 -
    siemens simatic hmi ktp mobile panels ktp700f firmware *
    siemens simatic hmi ktp mobile panels ktp700f -
    siemens simatic hmi ktp mobile panels ktp900 firmware *
    siemens simatic hmi ktp mobile panels ktp900 -
    siemens simatic hmi ktp mobile panels ktp900f firmware *
    siemens simatic hmi ktp mobile panels ktp900f -
    siemens simatic wincc (tia portal) *
    siemens simatic wincc runtime *
    siemens simatic wincc runtime *
    siemens simatic hmi tp firmware *
    siemens simatic hmi tp -
    siemens simatic hmi mp firmware *
    siemens simatic hmi mp -
    siemens simatic hmi op firmware *
    siemens simatic hmi op -
    siemens simatic wincc runtime *
    siemens simatic wincc runtime *
    siemens simatic hmi ktp mobile panels ktp400f -
    siemens simatic hmi ktp mobile panels ktp700 -
    siemens simatic hmi ktp mobile panels ktp700f -
    siemens simatic hmi ktp mobile panels ktp900 -
    siemens simatic hmi ktp mobile panels ktp900f -
    siemens simatic wincc (tia portal) *