Skip to content
COOEY

EXPOSURES › CVE-2016-8562

CVE-2016-8562

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-8562 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatchedics-ot

Siemens SIMATIC CP 1543-1 improper privilege management allowed remote denial of service.

A privileged attacker could remotely cause a denial of service on Siemens SIMATIC CP 1543-1 via improper privilege management. DIB orgs should care because this KEV vulnerability impacts industrial control systems, potentially disrupting critical infrastructure operations. Organizations must ensure all Siemens CP hardware is patched or replaced to prevent availability outages.

Shame score — A known vulnerability in industrial control hardware that was actively exploited in the wild, causing availability outages in critical infrastructure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cause a denial of service.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Mendix Cloud for Government
Siemens Government Technologies
In Process