← Vulnerability feed

Vulnerability record · CVE-2018-4848 · published 14 June 2018

CVE-2018-4848: Siemens scalance x300 firmware cross-site scripting vulnerability

Siemens · Scalance X300 Firmware

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.3). The integrated configuration web server of the affected devices could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed. At the stage of publishing this security advisory no public exploitation is known. The vendor has confirmed the vulnerability and provides mitigations to resolve it.

6.1 CVSS 3.0 Medium EPSS 1.0% · top 37.9% CWE-80 · CWE-80CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.3). The integrated configuration web server of the affected devices could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed. At the stage of publishing this security advisory no public exploitation is known. The vendor has confirmed the vulnerability and provides mitigations to resolve it.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/104494 Third Party AdvisoryVDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-480829.pdf Third Party AdvisoryVendor Advisory
http://www.securityfocus.com/bid/104494 Third Party AdvisoryVDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-480829.pdf Third Party AdvisoryVendor Advisory

Track CVE-2018-4848 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-29998Windriver vxworks out-of-bounds write vulnerabilityAn issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client.EPSS 2.4%9.1CVE-2019-6569Siemens scalance x-200 firmware vulnerabilityThe monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network. An attac…EPSS 1.3%8.8CVE-2018-4833Siemens rfid 181-eip firmware heap-based buffer overflow vulnerabilityA vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SI…EPSS 0.95%8.6CVE-2019-10942Siemens scalance x-200 firmware uncontrolled resource consumption vulnerabilityA vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch fam…EPSS 1.4%8.6CVE-2018-13807Siemens scalance x408 firmware improper input validation vulnerabilityA vulnerability has been identified in SCALANCE X300 (All versions < V4.0.0), SCALANCE X408 (All versions < V4.0.0), SCALANCE X414 (All versions). Th…EPSS 4.2%7.1CVE-2017-2681Siemens simatic cp 343-1 std firmware uncontrolled resource consumption vulnerabilitySpecially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of…EPSS 0.91%7.1CVE-2017-2680Siemens simatic cp 343-1 std firmware uncontrolled resource consumption vulnerabilitySpecially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2)…EPSS 1.1%5.5CVE-2019-6567Siemens scalance x-200 firmware insufficiently protected credentials vulnerabilityA vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch fam…EPSS 0.30%

Source: NIST National Vulnerability Database (record CVE-2018-4848), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.