← Vulnerability feed

Vulnerability record · CVE-2018-4833 · published 14 June 2018

CVE-2018-4833: Siemens rfid 181-eip firmware heap-based buffer overflow vulnerability

Siemens · Rfid 181 Eip Firmware

A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.6), SCALANCE X-300 switch family (incl. SIPLUS NET variants) (All versions < V4.1.3), SCALANCE X408 (All versions < V4.1.3), SCALANCE X414 (All versions), SIMATIC RF182C (All versions). Unprivileged remote attackers located in the same local network segment (OSI Layer 2) could gain remote code execution on the affected products by sending a specially crafted DHCP response to a client's DHCP request.

8.8 CVSS 3.0 High EPSS 0.95% · top 40.2% CWE-122 · Heap-based buffer overflowCWE-20 · Improper input validation
8.8CVSS 3.0 base score, v2 5.8
0.95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.6), SCALANCE X-300 switch family (incl. SIPLUS NET variants) (All versions < V4.1.3), SCALANCE X408 (All versions < V4.1.3), SCALANCE X414 (All versions), SIMATIC RF182C (All versions). Unprivileged remote attackers located in the same local network segment (OSI Layer 2) could gain remote code execution on the affected products by sending a specially crafted DHCP response to a client's DHCP request.

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-4833 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2019-13933Siemens scalance x-200rna firmware missing authentication for critical function vulnerabilityA vulnerability has been identified in SCALANCE X204RNA (HSR), SCALANCE X204RNA (PRP), SCALANCE X204RNA EEC (HSR), SCALANCE X204RNA EEC (PRP), SCALAN…EPSS 1.4%8.0CVE-2013-3633Siemens scalance x200irt firmware permissions and access controls vulnerabilityA vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V…EPSS 1.2%7.8CVE-2019-16905Openbsd openssh integer overflow vulnerabilityOpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or ser…EPSS 2.2%7.5CVE-2013-3634Siemens scalance x200irt firmware improper input validation vulnerabilityA vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V…EPSS 1.4%7.1CVE-2017-2681Siemens simatic cp 343-1 std firmware uncontrolled resource consumption vulnerabilitySpecially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of…EPSS 0.91%7.1CVE-2017-2680Siemens simatic cp 343-1 std firmware uncontrolled resource consumption vulnerabilitySpecially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2)…EPSS 1.1%6.8CVE-2019-6109Openbsd openssh vulnerabilityAn issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker)…EPSS 3.8%6.8CVE-2019-6110Openbsd openssh vulnerabilityIn OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manip…EPSS 21%

Source: NIST National Vulnerability Database (record CVE-2018-4833), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.