CVE-2016-8562
KEVlargeUnauthorized SNMP Write Flaw in Siemens SIMATIC CP 1543-1 (DoS)
CISA: Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability
Siemens SIMATIC CP 1543-1 and SIPLUS NET CP 1543-1 communication processors running firmware below V2.0.28 permit writes to SNMP variables on UDP port 161 that should be read-only and configurable only through TIA Portal — an improper privilege management flaw. An attacker who already has some SNMP access (low privileges, per the CVSS vector) can trigger the issue only under special conditions, reflected in the high attack complexity rating, by sending crafted SNMP write requests. A successful write can alter the module's runtime state, reducing availability or causing a denial of service; the CVSS 3.1 score of 7.5 (high) reflects high impact to confidentiality, integrity, and availability. Any deployment of the affected firmware is exposed, with the greatest risk where SNMP on the module is reachable from networks an attacker can access. The flaw is being exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03 — and EPSS assigns a 3.6% probability of exploitation in the next 30 days (89th percentile), though no public proof-of-concept is known.
What to do: Update SIMATIC CP 1543-1 and SIPLUS NET CP 1543-1 firmware to V2.0.28 or later per Siemens instructions, as required by CISA's KEV required action. Until patched, restrict access to UDP port 161 with access control lists or firewall rules, confirm SNMP community strings are not default or guessable, and audit installed firmware versions through TIA Portal to identify remaining unpatched units.
| Siemens SIMATIC CP 1543-1 firmware | All versions < V2.0.28 |
| Siemens SIPLUS NET CP 1543-1 firmware | All versions < V2.0.28 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special conditions it was possible to write SNMP variables on port 161/udp which should be read-only and should only be configured with TIA-Portal. A write to these variables could reduce the availability or cause a denial-of-service.
- Affected
- Siemens SIMATIC CP
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- siemens
- Products
- simatic cp 1543-1 firmware, siplus net cp 1543-1 firmware
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.