CVE Feed

    Dashboard / CVE / CVE-2015-8214

    CVE-2015-8214

    A vulnerability has been identified in SIMATIC NET CP 342-5 (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Advanced (incl. SIPLUS variants) (All versions < V3.0.44), SIMATIC NET CP 343-1 Lean (incl. SIPLUS variants) (All versions < V3.1.1), SIMATIC NET CP 343-1 Standard (incl. SIPLUS variants) (All versions < V3.1.1), SIMATIC NET CP 443-1 Advanced (incl. SIPLUS variants) (All versions < V3.2.9), SIMATIC NET CP 443-1 Standard (incl. SIPLUS variants) (All versions < V3.2.9), SIMATIC NET CP 443-5 Basic (incl. SIPLUS variants) (All versions), SIMATIC NET CP 443-5 Extended (All versions), TIM 3V-IE / TIM 3V-IE Advanced (incl. SIPLUS NET variants) (All versions < V2.6.0), TIM 3V-IE DNP3 (incl. SIPLUS NET variants) (All versions < V3.1.0), TIM 4R-IE (incl. SIPLUS NET variants) (All versions < V2.6.0), TIM 4R-IE DNP3 (incl. SIPLUS NET variants) (All versions < V3.1.0). The implemented access protection level enforcement of the affected communication processors (CP) could possibly allow unauthenticated users to perform administrative operations on the CPs if network access (port 102/TCP) is available and the CPs' configuration was stored on their corresponding CPUs.

    Published:Nov 27, 2015
    Last Modified:Apr 12, 2025
    EPS:Nov 27, 2015
    EPSS Score:0.01347
    CVSS Score:9.7

    Affected Products

    Vendor
    Siemens
    Product
    Simatic Cp 343-1
    Vendor
    Siemens
    Product
    Simatic Cp 343-1 Firmware
    Vendor
    Siemens
    Product
    Simatic Cp 443-1
    Vendor
    Siemens
    Product
    Simatic Cp 443-1 Firmware
    Vendor
    Siemens
    Product
    Simatic Tim 3v-ie
    Vendor
    Siemens
    Product
    Simatic Tim 3v-ie Firmware
    Vendor
    Siemens
    Product
    Simatic Tim 4r-ie
    Vendor
    Siemens
    Product
    Simatic Tim 4r-ie Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High