CVE-2018-3991: Siemens SIMATIC Wincc Open Architecture
Critical severity, CVSS 9.8. EPSS: 34.3% chance of exploitation in the next 30 days.
An exploitable heap overflow vulnerability exists in the WkbProgramLow function of WibuKey Network server management, version 6.40.2402.500. A specially crafted TCP packet can cause a heap overflow, potentially leading to remote code execution. An attacker can send a malformed TCP packet to trigger this vulnerability.
Affected products
- Siemens SIMATIC Wincc Open Architecture: version 3.14 only; version 3.15 only; version 3.16 only
- Wibu Wibukey: version 6.40.2402.500 only
Published 2019-02-05. Last modified 2026-06-17.