CVE-2018-4856

A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with administrative access to the device's management interface could lock out legitimate users. Manual interaction is required to restore the access of legitimate users.
References
Link Resource
http://www.securityfocus.com/bid/104672 Third Party Advisory VDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-197012.pdf Mitigation Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:siclock_tc400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:siclock_tc400:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:siclock_tc100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:siclock_tc100:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-07-03 14:29

Updated : 2024-02-28 16:25


NVD link : CVE-2018-4856

Mitre link : CVE-2018-4856

CVE.ORG link : CVE-2018-4856


JSON object : View

Products Affected

siemens

  • siclock_tc100_firmware
  • siclock_tc100
  • siclock_tc400_firmware
  • siclock_tc400
CWE
NVD-CWE-noinfo CWE-287

Improper Authentication