CVE Feed

    Dashboard / CVE / CVE-2016-4785

    CVE-2016-4785

    A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02. The integrated web server (port 80/tcp) of the affected devices could allow remote attackers to obtain a limited amount of device memory content if network access was obtained. This vulnerability only affects EN100 Ethernet module included in SIPROTEC4 and SIPROTEC Compact devices.

    Published:May 31, 2016
    Last Modified:Apr 12, 2025
    EPS:May 31, 2016
    EPSS Score:0.02402
    CVSS Score:5.3

    Affected Products

    Vendor
    Siemens
    Product
    Siprotec 4 En100
    Vendor
    Siemens
    Product
    Siprotec Compact Model
    Vendor
    Siemens
    Product
    Siprotec Compact Model 7rw80
    Vendor
    Siemens
    Product
    Siprotec Compact Model 7sd80
    Vendor
    Siemens
    Product
    Siprotec Compact Model 7sj80
    Vendor
    Siemens
    Product
    Siprotec Compact Model 7sj81
    Vendor
    Siemens
    Product
    Siprotec Compact Model 7sk80
    Vendor
    Siemens
    Product
    Siprotec Compact Model 7sk81
    Vendor
    Siemens
    Product
    Siprotec Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High