CVE-2016-8672
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.2.17), SIMATIC S7-300 PN/DP CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP CPU family (incl. SIPLUS variants) (All versions). The integrated web server delivers cookies without the "secure" flag. Modern browsers interpreting the flag would mitigate potential data leakage in case of clear text transmission.
Se ha identificado una vulnerabilidad en SIMATIC CP 343-1 Advanced (incluida la variante SIPLUS NET) (Todas las versiones anteriores a la versión V3.0.53), SIMATIC CP 443-1 Advanced (incluida la variante SIPLUS NET) (Todas las versiones anteriores a la versión fV3.2.17), Familia de CPU SIMATIC S7-300 PN / DP (incluidas las variantes SIPLUS) (todas las versiones), familia de CPU SIMATIC S7-400 PN / DP (incluidas las variantes SIPLUS) (todas las versiones). El servidor web integrado entrega cookies sin la bandera "segura". Los navegadores modernos que interpretan la bandera mitigarían la posible fuga de datos en caso de transmisión de texto claro.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-10-15 CVE Reserved
- 2016-11-22 CVE Published
- 2023-08-06 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-603476.pdf | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Simatic Cp 343-1 Firmware Search vendor "Siemens" for product "Simatic Cp 343-1 Firmware" | - | advanced |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Cp 343-1 Search vendor "Siemens" for product "Simatic Cp 343-1" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic S7 300 Cpu Firmware Search vendor "Siemens" for product "Simatic S7 300 Cpu Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic S7 300 Cpu Search vendor "Siemens" for product "Simatic S7 300 Cpu" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic S7 400 Cpu Firmware Search vendor "Siemens" for product "Simatic S7 400 Cpu Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic S7 400 Cpu Search vendor "Siemens" for product "Simatic S7 400 Cpu" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Cp 443-1 Firmware Search vendor "Siemens" for product "Simatic Cp 443-1 Firmware" | - | advanced |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Cp 443-1 Search vendor "Siemens" for product "Simatic Cp 443-1" | - | - |
Safe
|