CVE-2018-4833 - CVE House
Back to Database
Status published High CVE-2018-4833

A vulnerability has been identified in RFID 181EIP (All versions),...

Vulnerability Description

A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.6), SCALANCE X-300 switch family (incl. SIPLUS NET variants) (All versions < V4.1.3), SCALANCE X408 (All versions < V4.1.3), SCALANCE X414 (All versions), SIMATIC RF182C (All versions). Unprivileged remote attackers located in the same local network segment (OSI Layer 2) could gain remote code execution on the affected products by sending a specially crafted DHCP response to a client's DHCP request.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-4833

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

RFID 181EIP, RUGGEDCOM Win, SCALANCE X-200 switch family (incl. SIPLUS NET variants), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants), SCALANCE X-200RNA switch family, SCALANCE X-300 switch family (incl. SIPLUS NET variants), SCALANCE X408, SCALANCE X414, SIMATIC RF182C
Vulnerable Versions:
All versions, V4.4, V4.5, V5.0, and V5.1, All versions < V5.2.3, All versions < V5.4.1, All versions < V3.2.6, All versions < V4.1.3

Timeline

Official Publish: June 14th, 2018
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)