CVE-2016-2201: Input Validation
Published Feb 8, 2016
·Updated
Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to bypass a replay protection mechanism via packets on TCP port 102.
Affected Software
15 affected components
Siemens Simatic S7-1500 Cpu Firmware=1.8.2
Siemens Simatic S7-1511-1 Pn Cpu
Siemens Simatic S7-1511c-1 Pn Cpu
Siemens Simatic S7-1511f-1 Pn Cpu
Siemens Simatic S7-1512c-1 Pn Cpu
Siemens Simatic S7-1513-1 Pn Cpu
Siemens Simatic S7-1513f-1 Pn Cpu
Siemens Simatic S7-1515-2 Pn Cpu
Siemens Simatic S7-1515f-2 Pn Cpu
Siemens Simatic S7-1516-3 Pn\/dp Cpu
Siemens Simatic S7-1516f-3 Pn\/dp Cpu
Siemens Simatic S7-1517-3 Pn\/dp Cpu
Siemens Simatic S7-1517f-3 Pn\/dp Cpu
Siemens Simatic S7-1518-4 Pn\/dp Cpu
Siemens Simatic S7-1518f-4 Pn\/dp Cpu
Event History
Feb 8, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2201?
CVE-2016-2201 is classified as a medium severity vulnerability.
2
How do I fix CVE-2016-2201?
To fix CVE-2016-2201, update the Siemens SIMATIC S7-1500 CPU devices to firmware version 1.8.3 or later.
3
Who is affected by CVE-2016-2201?
CVE-2016-2201 affects Siemens SIMATIC S7-1500 CPU devices running firmware versions prior to 1.8.3.
4
What kind of attacks can exploit CVE-2016-2201?
CVE-2016-2201 can be exploited by remote attackers to bypass a replay protection mechanism.
5
What is the attack vector for CVE-2016-2201?
The attack vector for CVE-2016-2201 is through packets sent to TCP port 102.