CVE-2018-4841 describes a critical authentication bypass vulnerability affecting all versions of Siemens TIM 1531 IRC devices prior to V1.1. A remote attacker with network access to ports 80/tcp or 443/tcp can perform administrative operations without authentication. This allows for potential denial-of-service, data manipulation, and configuration changes, earning a CVSS v3.1 score of 9.8 (CRITICAL). While no public exploits or active exploitation are known, and there is minimal community discussion or media coverage, Siemens has provided mitigations for this high-impact vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1CPE matchmatch criteria | cpe:2.3:o:siemens:tim_1531_irc_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.