CVE-2016-8562
גבוהה 7.5 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special conditions it was possible to write SNMP variables on port 161/udp which should be read-only and should only be configured with TIA-Portal. A write to these variables could reduce the availability or cause a denial-of-service.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 4% (אחוזון 100) נכון ל-24/7/2026
מוצרים מושפעים
siemens: simatic cp 1543-1 firmware; siemens: simatic cp 1543-1; siemens: siplus net cp 1543-1 firmware; siemens: siplus net cp 1543-1
קישורים
- http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-672373.pdf Broken LinkPatchVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-672373.pdf Vendor Advisory
- http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-672373.pdf Broken LinkPatchVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-672373.pdf Vendor Advisory
- http://www.securityfocus.com/bid/94436 Broken LinkThird Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-327-01 Third Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/94436 Broken LinkThird Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-327-01 Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource