SB2016090501 - Multiple vulnerabilities in Siemens SIPROTEC 4 and SIPROTEC Compact



SB2016090501 - Multiple vulnerabilities in Siemens SIPROTEC 4 and SIPROTEC Compact

Published: September 5, 2016 Updated: July 7, 2017

Security Bulletin ID SB2016090501
Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Security restrictions bypass (CVE-ID: CVE-2016-7112)

The vulnerability allows a remote attacker to bypass security restrictions.

The weakness exists due to an error related to EN100 Ethernet module. A remote attacker can send specially crafted HTTP request and bypass access restrictions.

Successful exploitation of the vulnerability results in administrative access to the system.

2) Denial of service (CVE-ID: CVE-2016-7113)

The vulnerability allows a remote attacker to cause DoS condition.

The weakness exists due to an error in the EN100 Ethernet module. A remote attacker can send specially crafted HTTP packets to TCP port 80 and cause the device to crash.

Successful exploitation of the vulnerability results in denial of service.

3) Security restrictions bypass (CVE-ID: CVE-2016-7114)

The vulnerability allows a remote attacker to bypass security restrictions.

The weakness exists due to an error related to EN100 Ethernet module. A remote attacker can send specially crafted HTTP request and bypass access restrictions.

Successful exploitation of the vulnerability results in administrative access to the system.

Remediation

Install update from vendor's website.