peter bassill · operator
$ cve CVE-2016-8562 JSON

CVE-2016-8562 KEV

7.5
HIGH · CVSS 3.1 · EPSS 3.6% (pctl 89)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-24.

Description

A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special conditions it was possible to write SNMP variables on port 161/udp which should be read-only and should only be configured with TIA-Portal. A write to these variables could reduce the availability or cause a denial-of-service.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS3.61% — more likely to be exploited than 89% of all CVEs
On CISA KEVyes — remediate by 2022-03-24
Public exploitnone known
Published2016-11-18
Last modified2026-06-17

CISA KEV

NameSiemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability
Added2022-03-03
Due2022-03-24
Vendor / productSiemens / SIMATIC CP
Ransomware usenone reported

Affected (4)

VendorProduct
siemenssimatic cp 1543-1
siemenssimatic cp 1543-1 firmware
siemenssiplus net cp 1543-1
siemenssiplus net cp 1543-1 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD