CVE-2016-9157: Input Validation
Published Dec 5, 2016
·Updated
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially lead to unauthenticated remote code execution by sending specially crafted packets to port 19234/TCP.
Affected Software
1 affected component
Siemens Sicam Pas\/pqs<8.09
Event History
Dec 5, 2016
CVE Published
via MITRE·08:09 AM
Data Sourced
via MITRE·08:09 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-9157?
CVE-2016-9157 has a high severity rating due to its potential for Denial of Service attacks and possible remote code execution.
2
How do I fix CVE-2016-9157?
To remediate CVE-2016-9157, update Siemens SICAM PAS to version 8.09 or later.
3
What could an attacker do with CVE-2016-9157?
An attacker could exploit CVE-2016-9157 to cause a Denial of Service condition or potentially execute arbitrary code remotely.
4
Which versions of Siemens SICAM PAS are affected by CVE-2016-9157?
CVE-2016-9157 affects all versions of Siemens SICAM PAS prior to 8.09.
5
What ports are involved in the vulnerability stated in CVE-2016-9157?
CVE-2016-9157 involves specially crafted packets sent to port 19234/TCP.