CVE-2016-8562: Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability
A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special conditions it was possible to write SNMP variables on port 161/udp which should be read-only and should only be configured with TIA-Portal. A write to these variables could reduce the availability or cause a denial-of-service.
Other sources
An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cause a denial of service.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure the device so SNMP variables are read-only and ensure SNMP variables are only modified/configured via TIA-Portal as intended.
Siemens SIMATIC CP 1543-1 / SIPLUS NET CP 1543-1 SNMP variable write access = read-only - Compensating control
Restrict network access to UDP port 161 (SNMP) to trusted management hosts only (e.g., via firewall/ACL) to prevent remote writes to SNMP variables.
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8562?
CVE-2016-8562 is classified as a high-severity vulnerability due to its potential impact on the security of affected devices.
How do I fix CVE-2016-8562?
To fix CVE-2016-8562, upgrade the firmware of SIMATIC CP 1543-1 and SIPLUS NET CP 1543-1 to version 2.0.28 or later.
What devices are affected by CVE-2016-8562?
CVE-2016-8562 affects all versions of SIMATIC CP 1543-1 and SIPLUS NET CP 1543-1 prior to version 2.0.28.
What does CVE-2016-8562 exploit?
CVE-2016-8562 exploits a flaw that allows writing to SNMP variables on port 161/udp which should be read-only.
Can CVE-2016-8562 be mitigated without a firmware patch?
Mitigating CVE-2016-8562 without a firmware patch is not recommended, as the patch addresses the core vulnerability.