← Back

CVE-2016-9154

nvd nist
Published: Dec 23, 2016Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D (All firmware versions < V6.00.046) and Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 for Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U (All firmware versions < V6.00.046) use a pseudo random number generator with insufficient entropy to generate certificates for HTTPS, potentially allowing remote attackers to reconstruct the corresponding private key.

Affected (6)

6 products
Configuration A
6 vulnerable · 6 platform
Vulnerable SoftwareAffected Versions
Up to 6.00.00
Up to 6.00.00
Up to 6.00.00
Up to 6.00.00
Up to 6.00.00
Up to 6.00.00
Running on/withPlatform Versions
Siemens
Desigo Web Module Pxa30 W0
All versions
Siemens
Desigo Web Module Pxa30 W1
All versions
Siemens
Desigo Web Module Pxa30 W2
All versions
Siemens
Desigo Web Module Pxa40 W0
All versions
Siemens
Desigo Web Module Pxa40 W1
All versions
Siemens
Desigo Web Module Pxa40 W2
All versions

References (6)

Source: productcert@siemens.com
Third Party AdvisoryVDB Entry
Source: productcert@siemens.com
MitigationVendor Advisory
Source: productcert@siemens.com
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.