Vulnerability Details CVE-2018-4855
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). Unencrypted storage of passwords in the client configuration files and during network transmission could allow an attacker in a privileged position to obtain access passwords.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 35.1%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.3
Products affected by CVE-2018-4855
-
cpe:2.3:h:siemens:siclock_tc100:-
-
cpe:2.3:h:siemens:siclock_tc400:-
-
cpe:2.3:o:siemens:siclock_tc100_firmware:-
-
cpe:2.3:o:siemens:siclock_tc400_firmware:-