← Back

CVE-2015-8214

nvd nist
Published: Nov 27, 2015Modified: May 6, 2026

JSON object

Loading...
9.7
Vector
AV:N/AC:L/Au:N/C:P/I:C/A:C
Exploitability: 10.0 / Impact: 9.5
Source: NVD

Description

A vulnerability has been identified in SIMATIC NET CP 342-5 (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Advanced (incl. SIPLUS variants) (All versions < V3.0.44), SIMATIC NET CP 343-1 Lean (incl. SIPLUS variants) (All versions < V3.1.1), SIMATIC NET CP 343-1 Standard (incl. SIPLUS variants) (All versions < V3.1.1), SIMATIC NET CP 443-1 Advanced (incl. SIPLUS variants) (All versions < V3.2.9), SIMATIC NET CP 443-1 Standard (incl. SIPLUS variants) (All versions < V3.2.9), SIMATIC NET CP 443-5 Basic (incl. SIPLUS variants) (All versions), SIMATIC NET CP 443-5 Extended (All versions), TIM 3V-IE / TIM 3V-IE Advanced (incl. SIPLUS NET variants) (All versions < V2.6.0), TIM 3V-IE DNP3 (incl. SIPLUS NET variants) (All versions < V3.1.0), TIM 4R-IE (incl. SIPLUS NET variants) (All versions < V2.6.0), TIM 4R-IE DNP3 (incl. SIPLUS NET variants) (All versions < V3.1.0). The implemented access protection level enforcement of the affected communication processors (CP) could possibly allow unauthenticated users to perform administrative operations on the CPs if network access (port 102/TCP) is available and the CPs' configuration was stored on their corresponding CPUs.

Affected (9)

4 products
Simatic Cp 443 1 Firmware
Simatic Tim 4r Ie Firmware
Simatic Cp 343 1 Firmware
Simatic Tim 3v Ie Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Siemens
All versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Cp 443 1
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Siemens
All versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Tim 4r Ie
All versions
Configuration C
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Siemens
Up to 3.0
All versions
Running on/withPlatform Versions
Siemens
Simatic Cp 343 1
All versions
Configuration D
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Siemens
All versions
All versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Tim 3v Ie
All versions

Related CWEs

References (8)

Timeline

No history available yet.