First published: Fri Dec 23 2016(Updated: )
Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D (All firmware versions < V6.00.046) and Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 for Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U (All firmware versions < V6.00.046) use a pseudo random number generator with insufficient entropy to generate certificates for HTTPS, potentially allowing remote attackers to reconstruct the corresponding private key.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens PXA30-W0 | <=6.00.00 | |
Siemens PXA30-W1 | <=6.00.00 | |
Siemens PXA30-W2 firmware | <=6.00.00 | |
Siemens Desigo Web module PXA40-W0 | <=6.00.00 | |
Siemens PXA40-W1 Firmware | <=6.00.00 | |
Siemens Desigo Web module PXA40-W2 | <=6.00.00 | |
Siemens Desigo Web module PXA30-W0 firmware | ||
Siemens PXA30-W1 | ||
Siemens PXA30-W2 | ||
Siemens PXA40-W0 | ||
Siemens Desigo Web module PXA40 | ||
Siemens PXA40-W2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9154 is rated as a high severity vulnerability due to the potential for remote exploitation.
To fix CVE-2016-9154, update the affected Siemens Desigo PX Web modules to firmware version 6.00.046 or higher.
CVE-2016-9154 affects Siemens Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2, PXA40-W0, PXA40-W1, and PXA40-W2 with firmware versions below 6.00.046.
CVE-2016-9154 is a remote code execution vulnerability that can be exploited by an attacker to gain unauthorized access.
No, the only effective mitigation for CVE-2016-9154 is to update to the latest firmware version.