MEDIUM · 5.3

CVE-2016-2201

Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to bypass a replay protection mechanism via packets on TCP port 102.

Vulnerability Description

Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to bypass a replay protection mechanism via packets on TCP port 102.

CVSS Score

5.3

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
SiemensSimatic S7-1500 Cpu Firmware1.8.2
SiemensSimatic S7-1511-1 Pn Cpu-
SiemensSimatic S7-1511C-1 Pn Cpu-
SiemensSimatic S7-1511F-1 Pn Cpu-
SiemensSimatic S7-1512C-1 Pn Cpu-
SiemensSimatic S7-1513-1 Pn Cpu-
SiemensSimatic S7-1513F-1 Pn Cpu-
SiemensSimatic S7-1515-2 Pn Cpu-
SiemensSimatic S7-1515F-2 Pn Cpu-
SiemensSimatic S7-1516-3 Pn\/Dp Cpu-
SiemensSimatic S7-1516F-3 Pn\/Dp Cpu-
SiemensSimatic S7-1517-3 Pn\/Dp Cpu-
SiemensSimatic S7-1517F-3 Pn\/Dp Cpu-
SiemensSimatic S7-1518-4 Pn\/Dp Cpu-
SiemensSimatic S7-1518F-4 Pn\/Dp Cpu-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-2201?

CVE-2016-2201 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to bypass a replay protection mechanism via packets on TCP port 102.

How severe is CVE-2016-2201?

CVE-2016-2201 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-2201?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Simatic S7-1500 Cpu Firmware, Siemens Simatic S7-1511-1 Pn Cpu, Siemens Simatic S7-1511C-1 Pn Cpu, Siemens Simatic S7-1511F-1 Pn Cpu, Siemens Simatic S7-1512C-1 Pn Cpu.