Vulnerability Description
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02. The integrated web server (port 80/tcp) of the affected devices could allow remote attackers to obtain a limited amount of device memory content if network access was obtained. This vulnerability only affects EN100 Ethernet module included in SIPROTEC4 and SIPROTEC Compact devices.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Siprotec 4 En100 | - |
| Siemens | Siprotec Compact Model | - |
| Siemens | Siprotec Firmware | 4.26 |
| Siemens | Siprotec Compact Model 7Rw80 | - |
| Siemens | Siprotec Compact Model 7Sd80 | - |
| Siemens | Siprotec Compact Model 7Sj80 | - |
| Siemens | Siprotec Compact Model 7Sj81 | - |
| Siemens | Siprotec Compact Model 7Sk80 | - |
| Siemens | Siprotec Compact Model 7Sk81 | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/90773
- http://www.securityfocus.com/bid/99471
- http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-547990.pdfVendor Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-16-140-02Third Party AdvisoryUS Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-17-187-03
- https://www.siemens.com/cert/pool/cert/siemens_security_advisory_SSA-323211.pdf
- http://www.securityfocus.com/bid/90773
- http://www.securityfocus.com/bid/99471
- http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-547990.pdfVendor Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-16-140-02Third Party AdvisoryUS Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-17-187-03
- https://www.siemens.com/cert/pool/cert/siemens_security_advisory_SSA-323211.pdf
FAQ
What is CVE-2016-4785?
CVE-2016-4785 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00...
How severe is CVE-2016-4785?
CVE-2016-4785 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-4785?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Siprotec 4 En100, Siemens Siprotec Compact Model, Siemens Siprotec Firmware, Siemens Siprotec Compact Model 7Rw80, Siemens Siprotec Compact Model 7Sd80.