CVE-2016-2846

Published on: 03/16/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:14 PM UTC

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Certain versions of Simatic S7 1200 Cpu from Siemens contain the following vulnerability:

Siemens SIMATIC S7-1200 CPU devices before 4.0 allow remote attackers to bypass a "user program block" protection mechanism via unspecified vectors.

  • CVE-2016-2846 has been assigned by [email protected] to track the vulnerability - currently rated as MEDIUM severity.

CVSS3 Score: 6.5 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED LOW LOW NONE

CVSS2 Score: 6.4 - MEDIUM

Access
Vector
Access
Complexity
Authentication
NETWORK LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
PARTIAL PARTIAL NONE

CVE References

Description Tags Link
cert-portal.siemens.com
application/pdf
CONFIRM cert-portal.siemens.com/productcert/pdf/ssa-833048.pdf
Siemens SIMATIC S7-1200 CPU Protection Mechanism Failure | ICS-CERT ics-cert.us-cert.gov
text/html
URL Logo MISC ics-cert.us-cert.gov/advisories/ICSA-16-075-01
Siemens Vendor Advisory
www.siemens.com
application/pdf
CONFIRM www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-833048.pdf

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
HardwareSiemensSimatic S7 1200 Cpu-AllAllAll
HardwareSiemensSimatic S7 1200 Cpu-AllAllAll
Operating
System
SiemensSimatic S7 Cpu 1200 FirmwareAllAllAllAll
  • cpe:2.3:h:siemens:simatic_s7_1200_cpu:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:simatic_s7_1200_cpu:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:simatic_s7_cpu_1200_firmware:*:*:*:*:*:*:*:*: