Remote Code Execution in Siemens EN100 Ethernet Module Firmware
CVE-2016-4785
5.3MEDIUM
Summary
The EN100 Ethernet Module firmware contains a vulnerability that permits remote attackers to access a limited portion of device memory if they can gain network access. This issue affects several firmware variants, specifically those below certain version thresholds, and is particularly concerning for installations using the SIPROTEC4 and SIPROTEC Compact devices. Organizations utilizing this firmware must take immediate action to mitigate risks associated with unauthorized access.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved