LiveActive security incident?Get immediate response
CVE Record

CVE-2018-4845: A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 syst...

A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens Healthineers Informatics products), RAPIDLab 1200 Series (All versions < V3.3 _with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (All versions >= V3.0 _with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (V2.4.X_with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (All versions =< V2.3 _with_ Siemens Healthineers Informatics products), RAPIDPoint 400 systems (All versions _with_ Siemens Healthineers Informatics products). Remote attackers with either local or remote credentialed access to the "Remote View" feature might be able to elevate their privileges, compromising confidentiality, integrity, and availability of the system. No special skills or user interaction are required to perform this attack. At the time of advisory publication, no public exploitation of this security vulnerability is known. Siemens Healthineers confirms the security vulnerability and provides mitigations to resolve the security issue.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2018-4845 affects Siemens Healthineers RAPIDLab and RAPIDPoint blood gas analyzer systems. A user with credentials to the Remote View feature could gain higher privileges and compromise confidentiality, integrity, or availability. This matters most in clinical environments where device reliability and patient-care workflows depend on these systems.

Executive priority

Treat this as a high-priority medical device exposure review, not an internet-wide emergency. The main urgency is confirming whether clinical analyzer systems are affected, whether Remote View is accessible, and whether Siemens mitigations have been applied.

Technical view

The issue is classified as CWE-284, improper access control. A local or remote credentialed attacker with Remote View access may elevate privileges on affected RAPIDLab 1200, RAPIDPoint 400, and RAPIDPoint 500 configurations. The source bundle provides no CVSS score. Siemens confirmed the issue and references mitigations in SSA-755010.

Likely exposure

Exposure is likely limited to healthcare environments operating affected Siemens Healthineers RAPIDLab or RAPIDPoint systems, especially where Remote View is enabled or reachable by credentialed users. The affected matrix varies by product version and Informatics product usage.

Exploitation context

The CVE states no special skills or user interaction are required, but the attacker needs local or remote credentialed access to Remote View. At advisory publication, Siemens reported no known public exploitation. The bundle does not indicate CISA KEV listing or current active exploitation.

Researcher notes

Evidence supports privilege escalation through Remote View with credentialed access. The source bundle does not provide CVSS vectors, exploit details, or exact remediation text. Avoid overstating exploit maturity; use Siemens SSA-755010 and CVE records as the authoritative references.

Mitigation direction

  • Review Siemens Healthineers SSA-755010 for product-specific mitigations.
  • Apply Siemens-confirmed mitigations for each affected system configuration.
  • Restrict Remote View access to authorized operational users only.
  • Review accounts with local or remote Remote View access.
  • Check Siemens guidance before assuming a patch path.

Validation and detection

  • Inventory RAPIDLab 1200, RAPIDPoint 400, and RAPIDPoint 500 systems.
  • Record software versions and Informatics product usage for each system.
  • Determine whether Remote View is enabled or remotely accessible.
  • Compare each device against the affected version matrix.
  • Confirm Siemens SSA-755010 mitigation status for each affected device.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-284: Authorization and privilege behavior lookup

Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2018-4845 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Siemens AGRAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems, RAPIDLab 1200 Series, RAPIDPoint 500 systems, RAPIDPoint 500 systems, RAPIDPoint 500 systems, RAPIDPoint 400 systemsRAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems : All versions _without_ use of Siemens Healthineers Informatics products, RAPIDLab 1200 Series : All versions < V3.3 _with_ Siemens Healthineers Informatics products, RAPIDPoint 500 systems : All versions >= V3.0 _with_ Siemens Healthineers Informatics products, RAPIDPoint 500 systems : V2.4.X _with_ Siemens Healthineers Informatics products, RAPIDPoint 500 systems : All versions =< V2.3 _with_ Siemens Healthineers Informatics products, RAPIDPoint 400 systems : All versions_with_ Siemens Healthineers Informatics productsListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-284 · source CWE mapping

Improper Access Control

Improper Access Control represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.