Remote Code Execution in Siemens EN100 Ethernet Module Firmware
CVE-2016-4785

5.3MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
31 May 2016

Summary

The EN100 Ethernet Module firmware contains a vulnerability that permits remote attackers to access a limited portion of device memory if they can gain network access. This issue affects several firmware variants, specifically those below certain version thresholds, and is particularly concerning for installations using the SIPROTEC4 and SIPROTEC Compact devices. Organizations utilizing this firmware must take immediate action to mitigate risks associated with unauthorized access.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.