CVE-2016-8672 Details
Description
A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.2.17), SIMATIC S7-300 PN/DP CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP CPU family (incl. SIPLUS variants) (All versions). The integrated web server delivers cookies without the "secure" flag. Modern browsers interpreting the flag would mitigate potential data leakage in case of clear text transmission.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-603476.pdf | CVE | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-603476.pdf | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| siemens simatic cp 343-1 firmware | All versions |
CPE
Remediation
| |
| siemens simatic cp 343-1 | All versions |
CPE
Remediation
| |
| siemens simatic s7 300 cpu firmware | All versions |
CPE
Remediation
| |
| siemens simatic s7 300 cpu | All versions |
CPE
Remediation
| |
| siemens simatic s7 400 cpu firmware | All versions |
CPE
Remediation
| |
| siemens simatic s7 400 cpu | All versions |
CPE
Remediation
| |
| siemens simatic cp 443-1 firmware | All versions |
CPE
Remediation
| |
| siemens simatic cp 443-1 | All versions |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 6, 2026 | Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 12, 2019 | CVE Modified | [email protected] |
| Dec 12, 2019 | CVE Modified | [email protected] |
| Dec 10, 2019 | CVE Modified | [email protected] |
| Mar 17, 2017 | CVE Modified | [email protected] |
| Dec 22, 2016 | CVE Modified | [email protected] |
| Nov 30, 2016 | Modified Analysis | [email protected] |
| Nov 28, 2016 | CVE Modified | [email protected] |
| Nov 23, 2016 | Initial Analysis | [email protected] |