CWE
400
Advisory Published
Updated

CVE-2016-8367

First published: Mon Feb 13 2017(Updated: )

An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe). An attacker can open multiple connections to a targeted web server and keep connections open preventing new connections from being made, rendering the web server unavailable during an attack.

Credit: ics-cert@hq.dhs.gov

Affected SoftwareAffected VersionHow to fix
Magelis Gtu Universal Panel Firmware
Schneider-electric Magelis Gtu Universal Panel Firmware
Schneider-electric Magelis Gto Advanced Optimum Panel
Schneider Electric Magelis XBT GT Advanced Touchscreen Panel
Schneider-electric Magelis Sto5 Small Panel
Schneider-electric Magelis Sto5 Small Panel Firmware
Schneider Electric Magelis Stu Small Panel Firmware
Schneider Electric Magelis Stu Small Panel Firmware
Schneider-electric Magelis Xbt Gh Advanced Hand-held Panel Firmware
Schneider-electric Magelis Xbt Gh Advanced Hand-held Panel Firmware
Schneider Electric Magelis XBT GK Advanced Touchscreen Panel With Keyboard Firmware
Schneider Electric Magelis XBT GK Advanced Touchscreen Panel With Keyboard
Schneider Electric Magelis XBT GT Advanced Touchscreen Panel
Schneider Electric Magelis XBT GT Advanced Touchscreen Panel
Schneider Electric Magelis XBT GTW Advanced Open Touchscreen Panel Firmware
Schneider Electric Magelis XBT GTW Advanced Open Touchscreen Panel Firmware
All of
Magelis Gtu Universal Panel Firmware
Schneider-electric Magelis Gtu Universal Panel Firmware
All of
Schneider-electric Magelis Gto Advanced Optimum Panel
Schneider Electric Magelis XBT GT Advanced Touchscreen Panel
All of
Schneider-electric Magelis Sto5 Small Panel
Schneider-electric Magelis Sto5 Small Panel Firmware
All of
Schneider Electric Magelis Stu Small Panel Firmware
Schneider Electric Magelis Stu Small Panel Firmware
All of
Schneider-electric Magelis Xbt Gh Advanced Hand-held Panel Firmware
Schneider-electric Magelis Xbt Gh Advanced Hand-held Panel Firmware
All of
Schneider Electric Magelis XBT GK Advanced Touchscreen Panel With Keyboard Firmware
Schneider Electric Magelis XBT GK Advanced Touchscreen Panel With Keyboard
All of
Schneider Electric Magelis XBT GT Advanced Touchscreen Panel
Schneider Electric Magelis XBT GT Advanced Touchscreen Panel
All of
Schneider Electric Magelis XBT GTW Advanced Open Touchscreen Panel Firmware
Schneider Electric Magelis XBT GTW Advanced Open Touchscreen Panel Firmware

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2016-8367?

    CVE-2016-8367 is rated as a high severity vulnerability affecting various Schneider Electric Magelis panel devices.

  • How do I fix CVE-2016-8367?

    To fix CVE-2016-8367, update the affected Schneider Electric Magelis HMI panels to the latest firmware version provided by Schneider Electric.

  • What types of devices are affected by CVE-2016-8367?

    CVE-2016-8367 affects several Schneider Electric devices including Magelis GTO, GTU, STO, STU, and XBT series panels.

  • What are the potential impacts of CVE-2016-8367?

    If exploited, CVE-2016-8367 could allow unauthorized access to the Schneider Electric Magelis HMI systems, potentially leading to information disclosure or denial of service.

  • Is CVE-2016-8367 currently being exploited in the wild?

    As of the latest updates, there have been no confirmed incidents of CVE-2016-8367 being actively exploited in the wild.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203