PT-2016-7222 · Siemens · Siprotec Merging Unit 6Mu80+1

Published

2016-09-06

·

Updated

2018-03-23

·

CVE-2016-7112

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firmware variant PROFINET IO for EN100 Ethernet module versions prior to V1.04.01 Firmware variant Modbus TCP for EN100 Ethernet module versions prior to V1.11.00 Firmware variant DNP3 TCP for EN100 Ethernet module versions prior to V1.03 Firmware variant IEC 104 for EN100 Ethernet module versions prior to V1.21 EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 versions prior to 1.02.02
Description A vulnerability has been identified that could allow attackers with network access to the device's web interface (port 80/tcp) to possibly circumvent authentication and perform certain administrative operations.
Recommendations For Firmware variant PROFINET IO for EN100 Ethernet module versions prior to V1.04.01, update to version V1.04.01 or later. For Firmware variant Modbus TCP for EN100 Ethernet module versions prior to V1.11.00, update to version V1.11.00 or later. For Firmware variant DNP3 TCP for EN100 Ethernet module versions prior to V1.03, update to version V1.03 or later. For Firmware variant IEC 104 for EN100 Ethernet module versions prior to V1.21, update to version V1.21 or later. For EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 versions prior to 1.02.02, update to version 1.02.02 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-7112

Affected Products

En100 Ethernet Module
Siprotec Merging Unit 6Mu80