CVE-2016-9154: High severity siemens pxa30-w0 vulnerability
Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D (All firmware versions < V6.00.046) and Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 for Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U (All firmware versions < V6.00.046) use a pseudo random number generator with insufficient entropy to generate certificates for HTTPS, potentially allowing remote attackers to reconstruct the corresponding private key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9154?
CVE-2016-9154 is rated as a high severity vulnerability due to the potential for remote exploitation.
How do I fix CVE-2016-9154?
To fix CVE-2016-9154, update the affected Siemens Desigo PX Web modules to firmware version 6.00.046 or higher.
What devices are affected by CVE-2016-9154?
CVE-2016-9154 affects Siemens Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2, PXA40-W0, PXA40-W1, and PXA40-W2 with firmware versions below 6.00.046.
What type of vulnerability is CVE-2016-9154?
CVE-2016-9154 is a remote code execution vulnerability that can be exploited by an attacker to gain unauthorized access.
Can CVE-2016-9154 be mitigated without a firmware update?
No, the only effective mitigation for CVE-2016-9154 is to update to the latest firmware version.