PT-2016-6139 · Siemens · Siprotec Merging Unit 6Mu80+1

Aleksandr Bersenev

+1

·

Publicado

2016-05-31

·

Atualizado

2018-03-23

·

CVE-2016-4785

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firmware variant PROFINET IO for EN100 Ethernet module versions prior to V1.04.01 Firmware variant Modbus TCP for EN100 Ethernet module versions prior to V1.11.00 Firmware variant DNP3 TCP for EN100 Ethernet module versions prior to V1.03 Firmware variant IEC 104 for EN100 Ethernet module versions prior to V1.21 EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 versions prior to 1.02.02
Description A vulnerability has been identified that could allow remote attackers to obtain a limited amount of device memory content if network access was obtained, affecting the integrated web server on port 80/tcp of the affected devices.
Recommendations For Firmware variant PROFINET IO for EN100 Ethernet module versions prior to V1.04.01, update to version V1.04.01 or later. For Firmware variant Modbus TCP for EN100 Ethernet module versions prior to V1.11.00, update to version V1.11.00 or later. For Firmware variant DNP3 TCP for EN100 Ethernet module versions prior to V1.03, update to version V1.03 or later. For Firmware variant IEC 104 for EN100 Ethernet module versions prior to V1.21, update to version V1.21 or later. For EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 versions prior to 1.02.02, update to version 1.02.02 or later. As a temporary workaround, consider restricting access to the integrated web server on port 80/tcp to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-4785

Produtos afetados

En100 Ethernet Module
Siprotec Merging Unit 6Mu80