PT-2016-3430 · Siemens · Siplus Net Cp 1543-1+1

Published

2016-11-18

·

Updated

2025-01-22

·

CVE-2016-8562

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Siemens SIMATIC CP 1543-1 versions prior to V2.0.28 SIPLUS NET CP 1543-1 versions prior to V2.0.28
Description A vulnerability has been identified in the software, related to improper privilege management and insufficient input validation. Under special conditions, it is possible to write SNMP variables on port 161/udp, which should be read-only and only configured with TIA-Portal. This could reduce availability or cause a denial-of-service. An attacker could exploit this vulnerability by sending specially crafted packets to port 161/udp, potentially leading to a denial-of-service.
Recommendations For Siemens SIMATIC CP 1543-1 versions prior to V2.0.28, update to version V2.0.28 or later to resolve the issue. For SIPLUS NET CP 1543-1 versions prior to V2.0.28, update to version V2.0.28 or later to resolve the issue. As a temporary workaround, consider restricting access to port 161/udp to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-04011
CVE-2016-8562

Affected Products

Simatic Cp 1543Sp-1
Siplus Net Cp 1543-1