Vulnerability in SIMATIC S7-300 and S7-400 CPU Families by Siemens
CVE-2016-9159
5.9MEDIUM
Key Information:
Summary
A vulnerability exists in the Siemens SIMATIC S7-300 and S7-400 CPU families, allowing an attacker with network access via port 102/tcp (ISO-TSAP) or Profibus to potentially obtain sensitive credentials from the programmable logic controller (PLC). This issue affects various models, including related SIPLUS variants, if configured with protection-level 2. It is critical for users of these devices to assess their environment and take necessary precautions to safeguard against unauthorized access.
Affected Version(s)
SIMATIC S7-300 CPU family All versions
SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) All versions
SIMATIC S7-400 PN/DP V6 and below CPU family (incl. SIPLUS variants) All versions
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved