CVE-2018-4850 - CVE House
Back to Database
Status published High CVE-2018-4850

A vulnerability has been identified in SIMATIC S7-400 (incl. F)...

Vulnerability Description

A vulnerability has been identified in SIMATIC S7-400 (incl. F) CPU hardware version 4.0 and below (All versions), SIMATIC S7-400 (incl. F) CPU hardware version 5.0 (All firmware versions < V5.2), SIMATIC S7-400H CPU hardware version 4.5 and below (All versions). The affected CPUs improperly validate S7 communication packets which could cause a Denial-of-Service condition of the CPU. The CPU will remain in DEFECT mode until manual restart.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-4850

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SIMATIC S7-400 (incl. F) CPU hardware version 4.0 and below, SIMATIC S7-400 (incl. F) CPU hardware version 5.0, SIMATIC S7-400H CPU hardware version 4.5 and below
Vulnerable Versions:
SIMATIC S7-400 (incl. F) CPU hardware version 4.0 and below : All versions, SIMATIC S7-400 (incl. F) CPU hardware version 5.0 : All firmware versions < V5.2, SIMATIC S7-400H CPU hardware version 4.5 and below : All versions

Timeline

Official Publish: May 16th, 2018
Last Modified: September 16th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)