Back

CVE-2018-4841

CRITICAL

A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1). A remote attacker with network access to port 80/tcp or port 443/tcp could perform administrative operations on the device without prior authentication. Successful exploitation could allow to cause a denial-of-service, or read and manipulate data as well as configuration settings of the affected device. At the stage of publishing this security advisory no public exploitation is known. Siemens provides mitigations to resolve it.

Published: Mar 29, 2018 Modified: Jun 17, 2026
CWE-303 CWE-287

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
siemens tim_1531_irc_firmware * < 1.1

GitHub Security Advisory GHSA-vj79-837c-gmf4

A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1). A remote attacker with...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 4.76%

Top 9% most likely to be exploited

Threat Score 40.6 / 100

Data Sources

NVD EPSS GitHub