CVE-2016-4785
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02. The integrated web server (port 80/tcp) of the affected devices could allow remote attackers to obtain a limited amount of device memory content if network access was obtained. This vulnerability only affects EN100 Ethernet module included in SIPROTEC4 and SIPROTEC Compact devices.
Se ha identificado una vulnerabilidad en la variante de Firmware PROFINET IO para los módulos EN100 Ethernet: en todas las versiones anteriores a V1.04.01; la variante de Firmware Modbus TCP para los módulos EN100 Ethernet: en todas las versiones anteriores a V1.11.00; la variante de Firmware v TCP para los módulos EN100 Ethernet: en todas las versiones anteriores a V1.03; la variante de Firmware IEC 104 para los módulos EN100 Ethernet: en todas las versiones anteriores a V1.21 y el módulo EN100 Ethernet incluido en SIPROTEC Merging Unit 6MU80: todas las versiones anteriores a la 1.02.02. El servidor web integrado (puerto 80/tcp) de los dispositivos afectados podría permitir que los atacantes remotos obtengan una cantidad limitada de contenido de la memoria si obtienen acceso de red. Esta vulnerabilidad solo afecta al módulo EN100 Ethernet incluido en los dispositivos SIPROTEC4 y SIPROTEC Compact.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-05-11 CVE Reserved
- 2016-05-31 CVE Published
- 2023-03-07 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/90773 | Vdb Entry | |
http://www.securityfocus.com/bid/99471 | Vdb Entry | |
https://ics-cert.us-cert.gov/advisories/ICSA-16-140-02 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-17-187-03 | X_refsource_misc | |
https://www.siemens.com/cert/pool/cert/siemens_security_advisory_SSA-323211.pdf | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-547990.pdf | 2018-03-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Siprotec Firmware Search vendor "Siemens" for product "Siprotec Firmware" | 4.26 Search vendor "Siemens" for product "Siprotec Firmware" and version "4.26" | - |
Affected
| in | Siemens Search vendor "Siemens" | Siprotec 4 En100 Search vendor "Siemens" for product "Siprotec 4 En100" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siprotec Firmware Search vendor "Siemens" for product "Siprotec Firmware" | 4.26 Search vendor "Siemens" for product "Siprotec Firmware" and version "4.26" | - |
Affected
| in | Siemens Search vendor "Siemens" | Siprotec Compact Model Search vendor "Siemens" for product "Siprotec Compact Model" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siprotec Firmware Search vendor "Siemens" for product "Siprotec Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siprotec Compact Model 7rw80 Search vendor "Siemens" for product "Siprotec Compact Model 7rw80" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siprotec Firmware Search vendor "Siemens" for product "Siprotec Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siprotec Compact Model 7sd80 Search vendor "Siemens" for product "Siprotec Compact Model 7sd80" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siprotec Firmware Search vendor "Siemens" for product "Siprotec Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siprotec Compact Model 7sj80 Search vendor "Siemens" for product "Siprotec Compact Model 7sj80" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siprotec Firmware Search vendor "Siemens" for product "Siprotec Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siprotec Compact Model 7sj81 Search vendor "Siemens" for product "Siprotec Compact Model 7sj81" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siprotec Firmware Search vendor "Siemens" for product "Siprotec Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siprotec Compact Model 7sk80 Search vendor "Siemens" for product "Siprotec Compact Model 7sk80" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siprotec Firmware Search vendor "Siemens" for product "Siprotec Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siprotec Compact Model 7sk81 Search vendor "Siemens" for product "Siprotec Compact Model 7sk81" | - | - |
Safe
|