// For flags

CVE-2016-8673

 

Severity Score

8.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.2.17), SIMATIC S7-300 PN/DP CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP CPU family (incl. SIPLUS variants) (All versions). The integrated web server at port 80/TCP or port 443/TCP of the affected devices could allow remote attackers to perform actions with the permissions of an authenticated user, provided the targeted user has an active session and is induced to trigger the malicious request.

Se ha identificado una vulnerabilidad en SIMATIC CP 343-1 Advanced (incluida la variante SIPLUS NET) (Todas las versiones anteriores a la versión V3.0.53), SIMATIC CP 443-1 Advanced (incluida la variante SIPLUS NET) (Todas las versiones anteriores a la versión V3.2.17), Familia de CPU SIMATIC S7-300 PN / DP (incluidas las variantes SIPLUS) (todas las versiones), familia de CPU SIMATIC S7-400 PN / DP (incluidas las variantes SIPLUS) (todas las versiones). El servidor web integrado en el puerto 80 / TCP o el puerto 443 / TCP de los dispositivos afectados podría permitir a los atacantes remotos realizar acciones con los permisos de un usuario autenticado, siempre que el usuario objetivo tenga una sesión activa y se induzca a activar la solicitud maliciosa.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-10-15 CVE Reserved
  • 2016-11-23 CVE Published
  • 2023-08-06 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Siemens
Search vendor "Siemens"
Simatic S7 300 Cpu Firmware
Search vendor "Siemens" for product "Simatic S7 300 Cpu Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Simatic S7 300 Cpu
Search vendor "Siemens" for product "Simatic S7 300 Cpu"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 443-1 Firmware
Search vendor "Siemens" for product "Simatic Cp 443-1 Firmware"
-advanced
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 443-1
Search vendor "Siemens" for product "Simatic Cp 443-1"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 343-1 Firmware
Search vendor "Siemens" for product "Simatic Cp 343-1 Firmware"
-advanced
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 343-1
Search vendor "Siemens" for product "Simatic Cp 343-1"
--
Safe
Siemens
Search vendor "Siemens"
Simatic S7 400 Cpu Firmware
Search vendor "Siemens" for product "Simatic S7 400 Cpu Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Simatic S7 400 Cpu
Search vendor "Siemens" for product "Simatic S7 400 Cpu"
--
Safe