CVE-2018-4842 - CVE House
Back to Database
Status published Medium CVE-2018-4842

A vulnerability has been identified in SCALANCE X-200IRT switch family...

Vulnerability Description

A vulnerability has been identified in SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.3). A remote, authenticated attacker with access to the configuration web server could be able to store script code on the web site, if the HRP redundancy option is set. This code could be executed in the web browser of victims visiting this web site (XSS), affecting its confidentiality, integrity and availability. User interaction is required for successful exploitation, as the user needs to visit the manipulated web site. At the stage of publishing this security advisory no public exploitation is known. The vendor has confirmed the vulnerability and provides mitigations to resolve it.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-4842

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SCALANCE X-200IRT switch family (incl. SIPLUS NET variants), SCALANCE X-200RNA switch family, SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants)
Vulnerable Versions:
All versions < V5.4.1, All versions < V3.2.7, All versions < V4.1.3

Timeline

Official Publish: June 14th, 2018
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)