CVE-2016-7987
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
An issue was discovered in Siemens ETA4 firmware (all versions prior to Revision 08) of the SM-2558 extension module for: SICAM AK, SICAM TM 1703, SICAM BC 1703, and SICAM AK 3. Specially crafted packets sent to Port 2404/TCP could cause the affected device to go into defect mode. A cold start might be required to recover the system, a Denial-of-Service Vulnerability.
Affected (2)
Products: Siemens: Eta4 Firmware, Eta2 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 07 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sicam Ak 3 | All versions |
Siemens Sicam Bc 1703 | All versions |
Siemens Sicam Tm 1703 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 11.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sicam Ak | All versions |
Siemens Sicam Bc | All versions |
Siemens Sicam Tm | All versions |
Related CWEs
References (4)
Source: ics-cert@hq.dhs.gov
MitigationThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryUS Government Resource
Timeline
No history available yet.