Junglewise Threat Intelligence

CVE-2016-8562: Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability

CVE-2016-8562 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-03-03

Vendors: Siemens.

Executive brief

Siemens SIMATIC CP 1543-1 and SIPLUS NET CP 1543-1 devices contain an improper privilege management vulnerability where SNMP variables on port 161/udp that should be read-only can be written to. A privileged attacker can exploit this to remotely cause a denial-of-service or reduce system availability.

Affected products

  • Siemens SIMATIC CP 1543-1 All versions < V2.0.28
  • Siemens SIPLUS NET CP 1543-1 All versions < V2.0.28

Timeline

  • 2016-11-17: disclosed: Initial security focus and advisory publication date based on external references
  • 2022-03-03: kev added: Date added to CISA's Known Exploited Vulnerabilities Catalog
  • 2022-03-03: disclosed: NVD publication date