PT-2016-3430 · Siemens · Siplus Net Cp 1543-1+1
Published
2016-11-18
·
Updated
2025-01-22
·
CVE-2016-8562
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Siemens SIMATIC CP 1543-1 versions prior to V2.0.28
SIPLUS NET CP 1543-1 versions prior to V2.0.28
Description
A vulnerability has been identified in the software, related to improper privilege management and insufficient input validation. Under special conditions, it is possible to write SNMP variables on port 161/udp, which should be read-only and only configured with TIA-Portal. This could reduce availability or cause a denial-of-service. An attacker could exploit this vulnerability by sending specially crafted packets to port 161/udp, potentially leading to a denial-of-service.
Recommendations
For Siemens SIMATIC CP 1543-1 versions prior to V2.0.28, update to version V2.0.28 or later to resolve the issue.
For SIPLUS NET CP 1543-1 versions prior to V2.0.28, update to version V2.0.28 or later to resolve the issue.
As a temporary workaround, consider restricting access to port 161/udp to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic Cp 1543Sp-1
Siplus Net Cp 1543-1