← All CVEs

CVE-2016-8562

high · 7.5Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-03Remediation due 2022-03-24

A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special conditions it was possible to write SNMP variables on port 161/udp which should be read-only and should only be configured with TIA-Portal. A write to these variables could reduce the availability or cause a denial-of-service.

7.5
CVSS
3.6%
EPSS (exploit prob.)
89th
EPSS percentile
2016-11-18
Published

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
siemenssimatic_cp_1543-1_firmware< 2.0.28
siemenssimatic_cp_1543-1all versions
siemenssiplus_net_cp_1543-1_firmware< 2.0.28
siemenssiplus_net_cp_1543-1all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-8562