CVE-2018-4846 is a critical vulnerability affecting Siemens Healthineers RAPIDLab 1200, RAPIDPoint 400, and RAPIDPoint 500 systems, where a hardcoded factory account password allows unauthorized access over port 5900/tcp. With a CVSS score of 9.8, this vulnerability is easily exploitable remotely without user interaction or privileges, leading to severe impacts on confidentiality, integrity, and availability. While no public exploits or active exploitation are known, Siemens Healthineers has confirmed the issue and provided mitigations. Despite its severity, there is minimal community discussion or media coverage regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:siemens:rapidpoint_400_firmware:-:*:*:*:*:*:*:* | ||
<= 2.3CPE matchmatch criteria | cpe:2.3:o:siemens:rapidpoint_500_firmware:*:*:*:*:*:*:*:* | ||
>= 3.0CPE matchmatch criteria | cpe:2.3:o:siemens:rapidpoint_500_firmware:*:*:*:*:*:*:*:* | ||
< 3.3CPE matchmatch criteria | cpe:2.3:o:siemens:rapidlab_1200_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.