5.9
CVE-2016-9159
- EPSS 0.33%
- Published 17.12.2016 03:59:00
- Last modified 12.04.2025 10:46:40
- Source productcert@siemens.com
- Teams watchlist Login
- Open Login
A vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V6 and below CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 V6 and earlier CPU family (All versions), SIMATIC S7-400 V7 CPU family (All versions), SIMATIC S7-410 V8 CPU family (All versions), SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants) (All versions). An attacker with network access to port 102/tcp (ISO-TSAP) or via Profibus could obtain credentials from the PLC if protection-level 2 is configured on the affected devices.
Data is provided by the National Vulnerability Database (NVD)
Siemens ≫ Simatic S7-300 Cpu Firmware Version-
Siemens ≫ Simatic S7-300 Cpu 312 Version-
Siemens ≫ Simatic S7-300 Cpu 314 Version-
Siemens ≫ Simatic S7-300 Cpu 315-2 Dp Version-
Siemens ≫ Simatic S7-300 Cpu 317- 2 Dp Version-
Siemens ≫ Simatic S7-300 Cpu 314 Version-
Siemens ≫ Simatic S7-300 Cpu 315-2 Dp Version-
Siemens ≫ Simatic S7-300 Cpu 317- 2 Dp Version-
Siemens ≫ Simatic S7-400 Cpu Firmware Version-
Siemens ≫ Simatic S7-400 Cpu 412-1 Version-
Siemens ≫ Simatic S7-400 Cpu 412-2 Version-
Siemens ≫ Simatic S7-400 Cpu 412-2 Pn Version-
Siemens ≫ Simatic S7-400 Cpu 414-2 Version-
Siemens ≫ Simatic S7-400 Cpu 414-3 Version-
Siemens ≫ Simatic S7-400 Cpu 416-2 Version-
Siemens ≫ Simatic S7-400 Cpu 416-3 Version-
Siemens ≫ Simatic S7-400 Cpu 416f-2 Version-
Siemens ≫ Simatic S7-400 Cpu 417-4 Version-
Siemens ≫ Simatic S7-400 Cpu 412-2 Version-
Siemens ≫ Simatic S7-400 Cpu 412-2 Pn Version-
Siemens ≫ Simatic S7-400 Cpu 414-2 Version-
Siemens ≫ Simatic S7-400 Cpu 414-3 Version-
Siemens ≫ Simatic S7-400 Cpu 416-2 Version-
Siemens ≫ Simatic S7-400 Cpu 416-3 Version-
Siemens ≫ Simatic S7-400 Cpu 416f-2 Version-
Siemens ≫ Simatic S7-400 Cpu 417-4 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.33% | 0.525 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.