CVE-2016-5874: Input Validation
Published Jul 22, 2016
·Updated
Siemens SIMATIC NET PC-Software before 13 SP2 allows remote attackers to cause a denial of service (OPC UA service outage) via crafted TCP packets.
Affected Software
1 affected component
Siemens SIMATIC NET PC-Software<=13
Event History
Jul 22, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5874?
CVE-2016-5874 has a medium severity level as it can lead to a denial of service for the OPC UA service.
2
How do I fix CVE-2016-5874?
To fix CVE-2016-5874, upgrade Siemens SIMATIC NET PC Software to version 13 SP2 or later.
3
What software versions are affected by CVE-2016-5874?
CVE-2016-5874 affects Siemens SIMATIC NET PC Software versions prior to 13 SP2.
4
What type of attack does CVE-2016-5874 facilitate?
CVE-2016-5874 allows remote attackers to cause a denial of service via crafted TCP packets.
5
Is there a workaround for CVE-2016-5874?
There are no documented workarounds for CVE-2016-5874, so upgrading to the fixed version is recommended.