// For flags

CVE-2016-8367

 

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe). An attacker can open multiple connections to a targeted web server and keep connections open preventing new connections from being made, rendering the web server unavailable during an attack.

Ha sido descubierto un problema en Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, todas las versiones, Magelis GTU Universal Panel, todas las versiones, Magelis STO5xx y STU Small panels, todas las versiones, Magelis XBT GH Advanced Hand-held Panels, todas las versiones, Magelis XBT GK Advanced Touchscreen Panels con Keyboard, todas las versiones, Magelis XBT GT Advanced Touchscreen Panels, todas las versiones y Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe). Un atacante puede abrir mĂșltiples conexiones en un servidor web objetivo y mantener las conexiones abiertas impidiendo que se hagan nuevas conexiones, dejando el servidor web inutilizable durante un ataque.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-09-28 CVE Reserved
  • 2017-02-13 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-400: Uncontrolled Resource Consumption
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Schneider-electric
Search vendor "Schneider-electric"
Magelis Gtu Universal Panel Firmware
Search vendor "Schneider-electric" for product "Magelis Gtu Universal Panel Firmware"
--
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Magelis Gtu Universal Panel
Search vendor "Schneider-electric" for product "Magelis Gtu Universal Panel"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Magelis Gto Advanced Optimum Panel Firmware
Search vendor "Schneider-electric" for product "Magelis Gto Advanced Optimum Panel Firmware"
--
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Magelis Gto Advanced Optimum Panel
Search vendor "Schneider-electric" for product "Magelis Gto Advanced Optimum Panel"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Magelis Sto5 Small Panel Firmware
Search vendor "Schneider-electric" for product "Magelis Sto5 Small Panel Firmware"
--
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Magelis Sto5 Small Panel
Search vendor "Schneider-electric" for product "Magelis Sto5 Small Panel"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Magelis Stu Small Panel Firmware
Search vendor "Schneider-electric" for product "Magelis Stu Small Panel Firmware"
--
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Magelis Stu Small Panel
Search vendor "Schneider-electric" for product "Magelis Stu Small Panel"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Magelis Xbt Gh Advanced Hand-held Panel Firmware
Search vendor "Schneider-electric" for product "Magelis Xbt Gh Advanced Hand-held Panel Firmware"
--
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Magelis Xbt Gh Advanced Hand-held Panel
Search vendor "Schneider-electric" for product "Magelis Xbt Gh Advanced Hand-held Panel"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Magelis Xbt Gk Advanced Touchscreen Panel With Keyboard Firmware
Search vendor "Schneider-electric" for product "Magelis Xbt Gk Advanced Touchscreen Panel With Keyboard Firmware"
--
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Magelis Xbt Gk Advanced Touchscreen Panel With Keyboard
Search vendor "Schneider-electric" for product "Magelis Xbt Gk Advanced Touchscreen Panel With Keyboard"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Magelis Xbt Gt Advanced Touchscreen Panel Firmware
Search vendor "Schneider-electric" for product "Magelis Xbt Gt Advanced Touchscreen Panel Firmware"
--
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Magelis Xbt Gt Advanced Touchscreen Panel
Search vendor "Schneider-electric" for product "Magelis Xbt Gt Advanced Touchscreen Panel"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Magelis Xbt Gtw Advanced Open Touchscreen Panel Firmware
Search vendor "Schneider-electric" for product "Magelis Xbt Gtw Advanced Open Touchscreen Panel Firmware"
--
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Magelis Xbt Gtw Advanced Open Touchscreen Panel
Search vendor "Schneider-electric" for product "Magelis Xbt Gtw Advanced Open Touchscreen Panel"
--
Safe