AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-4838

HIGH · CVSS 7.5 EPSS 1.43%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-03-08 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. Exploitation may require the attacker to be authenticated.

CVE
CVE-2018-4838
Severity
HIGH
CVSS
7.5
EPSS
1.43%

Original NVD Description

A vulnerability has been identified in EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module DNP3 variant (All versions < V1.04), EN100 Ethernet module PROFINET IO variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions < V1.22). The web interface (TCP/80) of affected devices allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to older versions with known vulnerabilities.

Related CVEs

Other vulnerabilities affecting the same vendor(s)