Vulnerabilities > CVE-2017-12739 - Insecure Default Initialization of Resource vulnerability in Siemens Sm-2556 Firmware

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
siemens
CWE-1188
critical

Summary

An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected devices could allow unauthenticated remote attackers to execute arbitrary code on the affected device.

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/144982/SA-20171114-0.txt
idPACKETSTORM:144982
last seen2017-11-14
published2017-11-14
reportersec-consult.com
sourcehttps://packetstormsecurity.com/files/144982/Siemens-SICAM-RTUs-SM-2556-COM-Modules-XSS-Bypass-Code-Execution.html
titleSiemens SICAM RTUs SM-2556 COM Modules XSS / Bypass / Code Execution