CVE-2016-4784: Infoleak
A vulnerability has been identified in firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02; SIPROTEC 7SJ686 : All versions < V 4.83; SIPROTEC 7UT686 : All versions < V 4.01; SIPROTEC 7SD686 : All versions < V 4.03; SIPROTEC 7SJ66 : All versions < V 4.20. The integrated web server (port 80/tcp) of the affected devices could allow remote attackers to obtain sensitive device information if network access was obtained.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4784?
CVE-2016-4784 has a medium severity rating due to its potential impact on the affected devices.
How do I fix CVE-2016-4784?
To fix CVE-2016-4784, update the firmware of the affected EN100 Ethernet module to a version >= V1.04.01 for PROFINET IO, >= V1.11.00 for Modbus TCP, or >= V1.03 for DNP3 TCP.
Which versions are affected by CVE-2016-4784?
CVE-2016-4784 affects all firmware versions of PROFINET IO for EN100 Ethernet module below V1.04.01, Modbus TCP below V1.11.00, and DNP3 TCP below V1.03.
What devices are impacted by CVE-2016-4784?
CVE-2016-4784 impacts firmware variants of the Siemens SIPROTEC series, particularly the EN100 Ethernet module.
Is my Siemens SIPROTEC Compact model vulnerable to CVE-2016-4784?
The Siemens SIPROTEC Compact models 7RW80, 7SD80, 7SJ80, 7SK81, and others are not vulnerable to CVE-2016-4784.