CVE-2016-8562

CVE Published 2016-11-18
Related CWE(s) CWE-20: Improper Input Validation
Related Vendor(s) siemens
Related Product(s) siplus_net_cp_1543-1_firmware, simatic_cp_1543-1_firmware
Exploitation Reported (CISA KEV) 2022-03-03
CVSS 3 Base Score 7.5 (HIGH)
CVSS 3 Attack Complexity HIGH
CVSS 3 Attack Vector NETWORK

A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special conditions it was possible to write SNMP variables on port 161/udp which should be read-only and should only be configured with TIA-Portal. A write to these variables could reduce the availability or cause a denial-of-service.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References