CVE-2016-9156: Input Validation
Published Dec 5, 2016
·Updated
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to upload, download, or delete files in certain parts of the file system by sending specially crafted packets to port 19235/TCP.
Affected Software
1 affected component
Siemens Sicam Pas\/pqs<8.09
Event History
Dec 5, 2016
CVE Published
via MITRE·08:09 AM
Data Sourced
via MITRE·08:09 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-9156?
CVE-2016-9156 is considered a high severity vulnerability due to the potential for remote file manipulation.
2
How do I fix CVE-2016-9156?
To mitigate CVE-2016-9156, upgrade to Siemens SICAM PAS version 8.09 or later.
3
What type of attacks can exploit CVE-2016-9156?
Attackers can exploit CVE-2016-9156 to remotely upload, download, or delete files in specific areas of the file system.
4
Which versions of Siemens SICAM PAS are affected by CVE-2016-9156?
All versions of Siemens SICAM PAS prior to version 8.09 are affected by CVE-2016-9156.
5
On what port does CVE-2016-9156 vulnerability operate?
CVE-2016-9156 operates on port 19235/TCP.