CVE-2016-8562
Siemens Simatic Cp 1543-1 Firmware ≤ 2.0.28
Raw vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2016-8562 is a high-severity an unspecified weakness vulnerability in Siemens Simatic Cp 1543-1 Firmware. Its CVSS base score is 7.5 (High).
Operationally, ranked in the top 12% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
The vulnerability CVE-2016-8562 affects Siemens SIMATIC CP 1543-1 and SIPLUS NET CP 1543-1 devices in all versions prior to V2.0.28. It permits writing to certain SNMP variables exposed on UDP port 161 that are designed to be read-only and configurable exclusively through TIA-Portal, under special conditions. Successful modification of these variables can degrade device availability or trigger a denial-of-service condition.
An attacker with network access and low privileges may exploit the flaw by sending crafted SNMP writes to the affected port. The CVSS vector indicates the attack requires high complexity yet can result in high impact across confidentiality, integrity, and availability when conditions are met.
Siemens security advisory SSA-672373 and the related ICS-CERT advisory ICSA-16-327-01 both direct users to apply firmware version V2.0.28 or later, which corrects the improper write access on the SNMP interface. The advisories are available at the Siemens and US-CERT reference URLs provided for the CVE.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2016-9410
Vulnerability Data
A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special conditions it was possible to write SNMP variables on port 161/udp which should be read-only and should…
more
only be configured with TIA-Portal. A write to these variables could reduce the availability or cause a denial-of-service.
- CWE(s)
- KEV Date Added
- 03 March 2022
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.