← Vulnerability feed

Vulnerability record · CVE-2018-4842 · published 14 June 2018

CVE-2018-4842: Siemens scalance x200irt firmware cross-site scripting vulnerability

Siemens · Scalance X200irt Firmware

A vulnerability has been identified in SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.3). A remote, authenticated attacker with access to the configuration web server could be able to store script code on the web site, if the HRP redundancy option is set. This code could be executed in the web browser of victims visiting this web site (XSS), affecting its confidentiality, integrity and availability. User interaction is required for successful exploitation, as the user needs to visit the manipulated web site. At the stage of publishing this security advisory no public exploitation is known. The vendor has confirmed the vulnerability and provides mitigations to resolve it.

4.8 CVSS 3.0 Medium EPSS 0.83% · top 44.2% CWE-79 · Cross-site scripting
4.8CVSS 3.0 base score, v2 3.5
0.83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.3). A remote, authenticated attacker with access to the configuration web server could be able to store script code on the web site, if the HRP redundancy option is set. This code could be executed in the web browser of victims visiting this web site (XSS), affecting its confidentiality, integrity and availability. User interaction is required for successful exploitation, as the user needs to visit the manipulated web site. At the stage of publishing this security advisory no public exploitation is known. The vendor has confirmed the vulnerability and provides mitigations to resolve it.

CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-4842 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-29998Windriver vxworks out-of-bounds write vulnerabilityAn issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client.EPSS 2.4%8.8CVE-2018-4833Siemens rfid 181-eip firmware heap-based buffer overflow vulnerabilityA vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SI…EPSS 0.95%8.6CVE-2018-13807Siemens scalance x408 firmware improper input validation vulnerabilityA vulnerability has been identified in SCALANCE X300 (All versions < V4.0.0), SCALANCE X408 (All versions < V4.0.0), SCALANCE X414 (All versions). Th…EPSS 4.2%8.0CVE-2013-3633Siemens scalance x200irt firmware permissions and access controls vulnerabilityA vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V…EPSS 1.2%7.5CVE-2013-3634Siemens scalance x200irt firmware improper input validation vulnerabilityA vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V…EPSS 1.4%7.1CVE-2017-2681Siemens simatic cp 343-1 std firmware uncontrolled resource consumption vulnerabilitySpecially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of…EPSS 0.91%7.1CVE-2017-2680Siemens simatic cp 343-1 std firmware uncontrolled resource consumption vulnerabilitySpecially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2)…EPSS 1.1%6.1CVE-2018-4848Siemens scalance x300 firmware cross-site scripting vulnerabilityA vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch fam…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2018-4842), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.