← Vulnerability feed

Vulnerability record · CVE-2018-13807 · published 12 September 2018

CVE-2018-13807: Siemens scalance x408 firmware improper input validation vulnerability

Siemens · Scalance X408 Firmware

A vulnerability has been identified in SCALANCE X300 (All versions < V4.0.0), SCALANCE X408 (All versions < V4.0.0), SCALANCE X414 (All versions). The web interface on port 443/tcp could allow an attacker to cause a Denial-of-Service condition by sending specially crafted packets to the web server. The device will automatically reboot, impacting network availability for other devices. An attacker must have network access to port 443/tcp to exploit the vulnerability. Neither valid credentials nor interaction by a legitimate user is required to exploit the vulnerability. There is no confidentiality or integrity impact, only availability is temporarily impacted. This vulnerability could be triggered by publicly available tools.

8.6 CVSS 3.0 High EPSS 4.2% · top 9.4% CWE-20 · Improper input validation
8.6CVSS 3.0 base score, v2 7.8
4.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in SCALANCE X300 (All versions < V4.0.0), SCALANCE X408 (All versions < V4.0.0), SCALANCE X414 (All versions). The web interface on port 443/tcp could allow an attacker to cause a Denial-of-Service condition by sending specially crafted packets to the web server. The device will automatically reboot, impacting network availability for other devices. An attacker must have network access to port 443/tcp to exploit the vulnerability. Neither valid credentials nor interaction by a legitimate user is required to exploit the vulnerability. There is no confidentiality or integrity impact, only availability is temporarily impacted. This vulnerability could be triggered by publicly available tools.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/105331 Third Party AdvisoryVDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-447396.pdf Vendor Advisory
https://ics-cert.us-cert.gov/advisories/ICSA-18-254-05 Third Party AdvisoryUS Government ResourceVDB Entry
http://www.securityfocus.com/bid/105331 Third Party AdvisoryVDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-447396.pdf Vendor Advisory
https://ics-cert.us-cert.gov/advisories/ICSA-18-254-05 Third Party AdvisoryUS Government ResourceVDB Entry

Track CVE-2018-13807 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-29998Windriver vxworks out-of-bounds write vulnerabilityAn issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client.EPSS 2.4%8.8CVE-2018-4833Siemens rfid 181-eip firmware heap-based buffer overflow vulnerabilityA vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SI…EPSS 0.95%7.1CVE-2017-2681Siemens simatic cp 343-1 std firmware uncontrolled resource consumption vulnerabilitySpecially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of…EPSS 0.91%7.1CVE-2017-2680Siemens simatic cp 343-1 std firmware uncontrolled resource consumption vulnerabilitySpecially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2)…EPSS 1.1%6.1CVE-2018-4848Siemens scalance x300 firmware cross-site scripting vulnerabilityA vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch fam…EPSS 1.0%4.8CVE-2018-4842Siemens scalance x200irt firmware cross-site scripting vulnerabilityA vulnerability has been identified in SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch …EPSS 0.83%9.5CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2018-13807), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.