First published: Fri Nov 27 2015(Updated: )
A vulnerability has been identified in SIMATIC NET CP 342-5 (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Advanced (incl. SIPLUS variants) (All versions < V3.0.44), SIMATIC NET CP 343-1 Lean (incl. SIPLUS variants) (All versions < V3.1.1), SIMATIC NET CP 343-1 Standard (incl. SIPLUS variants) (All versions < V3.1.1), SIMATIC NET CP 443-1 Advanced (incl. SIPLUS variants) (All versions < V3.2.9), SIMATIC NET CP 443-1 Standard (incl. SIPLUS variants) (All versions < V3.2.9), SIMATIC NET CP 443-5 Basic (incl. SIPLUS variants) (All versions), SIMATIC NET CP 443-5 Extended (All versions), TIM 3V-IE / TIM 3V-IE Advanced (incl. SIPLUS NET variants) (All versions < V2.6.0), TIM 3V-IE DNP3 (incl. SIPLUS NET variants) (All versions < V3.1.0), TIM 4R-IE (incl. SIPLUS NET variants) (All versions < V2.6.0), TIM 4R-IE DNP3 (incl. SIPLUS NET variants) (All versions < V3.1.0). The implemented access protection level enforcement of the affected communication processors (CP) could possibly allow unauthenticated users to perform administrative operations on the CPs if network access (port 102/TCP) is available and the CPs' configuration was stored on their corresponding CPUs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SIMATIC CP 443-1 Std Firmware | ||
Siemens SIMATIC CP 443-1 Std Firmware | ||
Siemens Simatic CP443-1 Advanced Firmware | ||
Siemens SIMATIC TIM 4R-IE Firmware | ||
Siemens SIMATIC TIM 4R-IE Firmware | ||
Siemens TIM 4R-IE | ||
Siemens Simatic CP 343-1 | ||
Siemens Simatic CP 343-1 | <=3.0 | |
Siemens Simatic CP 343-1 Advanced | ||
Siemens TIM 3V-IE | ||
Siemens TIM 3V-IE | ||
Siemens TIM 3V-IE | ||
Siemens TIM 3V-IE |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8214 has been assigned a significant severity rating due to its potential impact on Siemens SIMATIC network components.
To fix CVE-2015-8214, you should update the affected Siemens SIMATIC devices to the latest firmware versions.
CVE-2015-8214 affects various Siemens SIMATIC NET CP models, including CP 342-5 and CP 343-1 across multiple firmware versions.
CVE-2015-8214 may allow unauthorized access to sensitive network configurations, leading to data breaches or system disruptions.
As of the latest updates, there have been no public reports indicating active exploitation of CVE-2015-8214.