CVE-2016-4784
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02; SIPROTEC 7SJ686 : All versions < V 4.83; SIPROTEC 7UT686 : All versions < V 4.01; SIPROTEC 7SD686 : All versions < V 4.03; SIPROTEC 7SJ66 : All versions < V 4.20. The integrated web server (port 80/tcp) of the affected devices could allow remote attackers to obtain sensitive device information if network access was obtained.
Se ha identificado una vulnerabilidad en la variante de Firmware PROFINET IO para los módulos EN100 Ethernet: en todas las versiones anteriores a V1.04.01; la variante de Firmware Modbus TCP para los módulos EN100 Ethernet: en todas las versiones anteriores a V1.11.00; la variante de Firmware v TCP para los módulos EN100 Ethernet: en todas las versiones anteriores a V1.03; la variante de Firmware IEC 104 para los módulos EN100 Ethernet: en todas las versiones anteriores a V1.21 y el módulo EN100 Ethernet incluido en SIPROTEC Merging Unit 6MU80: todas las versiones anteriores a la 1.02.02; SIPROTEC 7SJ686: todas las versiones anteriores a la V 4.83; SIPROTEC 7UT686: todas las versiones anteriores a la V 4.01; SIPROTEC 7SD686: todas las versiones anteriores a la V 4.03 y SIPROTEC 7SJ66: todas las versiones anteriores a la V 4.20. El servidor web integrado (puerto 80/tcp) de los dispositivos afectados podría permitir que los atacantes remotos obtengan información sensible del dispositivo si obtienen acceso de red.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-05-11 CVE Reserved
- 2016-05-31 CVE Published
- 2023-03-07 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/90773 | Vdb Entry | |
http://www.securityfocus.com/bid/99471 | Vdb Entry | |
https://ics-cert.us-cert.gov/advisories/ICSA-16-140-02 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-17-187-03 | X_refsource_misc | |
https://www.siemens.com/cert/pool/cert/siemens_security_advisory_SSA-323211.pdf | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-547990.pdf | 2018-03-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Siprotec Firmware Search vendor "Siemens" for product "Siprotec Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siprotec Compact Model 7rw80 Search vendor "Siemens" for product "Siprotec Compact Model 7rw80" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siprotec Firmware Search vendor "Siemens" for product "Siprotec Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siprotec Compact Model 7sd80 Search vendor "Siemens" for product "Siprotec Compact Model 7sd80" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siprotec Firmware Search vendor "Siemens" for product "Siprotec Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siprotec Compact Model 7sj80 Search vendor "Siemens" for product "Siprotec Compact Model 7sj80" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siprotec Firmware Search vendor "Siemens" for product "Siprotec Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siprotec Compact Model 7sj81 Search vendor "Siemens" for product "Siprotec Compact Model 7sj81" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siprotec Firmware Search vendor "Siemens" for product "Siprotec Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siprotec Compact Model 7sk80 Search vendor "Siemens" for product "Siprotec Compact Model 7sk80" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siprotec Firmware Search vendor "Siemens" for product "Siprotec Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siprotec Compact Model 7sk81 Search vendor "Siemens" for product "Siprotec Compact Model 7sk81" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siprotec Firmware Search vendor "Siemens" for product "Siprotec Firmware" | 4.26 Search vendor "Siemens" for product "Siprotec Firmware" and version "4.26" | - |
Affected
| in | Siemens Search vendor "Siemens" | Siprotec 4 En100 Search vendor "Siemens" for product "Siprotec 4 En100" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siprotec Firmware Search vendor "Siemens" for product "Siprotec Firmware" | 4.26 Search vendor "Siemens" for product "Siprotec Firmware" and version "4.26" | - |
Affected
| in | Siemens Search vendor "Siemens" | Siprotec Compact Model En100 Search vendor "Siemens" for product "Siprotec Compact Model En100" | - | - |
Safe
|