CVE-2016-8367
Last modified
CVE-2016-8367 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe). An attacker can open multiple connections to a targeted web server and keep connections open preventing new connections from being made, rendering the web server unavailable during an attack.. EPSS estimates a 4.30% chance of exploitation in the next 30 days.
Description
An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe). An attacker can open multiple connections to a targeted web server and keep connections open preventing new connections from being made, rendering the web server unavailable during an attack.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Magelis Gtu Universal Panel Firmware | All versions |
| Schneider-Electric | Magelis Gto Advanced Optimum Panel Firmware | All versions |
| Schneider-Electric | Magelis Sto5 Small Panel Firmware | All versions |
| Schneider-Electric | Magelis Stu Small Panel Firmware | All versions |
| Schneider-Electric | Magelis Xbt Gh Advanced Hand-Held Panel Firmware | All versions |
| Schneider-Electric | Magelis Xbt Gk Advanced Touchscreen Panel With Keyboard Firmware | All versions |
| Schneider-Electric | Magelis Xbt Gt Advanced Touchscreen Panel Firmware | All versions |
| Schneider-Electric | Magelis Xbt Gtw Advanced Open Touchscreen Panel Firmware | All versions |
References
- http://www.securityfocus.com/bid/94093Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-308-02Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/94093Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-308-02Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-8367?
How severe is CVE-2016-8367?
How do I fix CVE-2016-8367?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-8361An issue was discovered in Lynxspring JENEsys BAS Bridge ver…
- CVE-2016-8362An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK…
- CVE-2016-8363An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK…
- CVE-2016-8364An issue was discovered in IBHsoftec S7-SoftPLC prior to 4.1…
- CVE-2016-8365OSIsoft PI System software (Applications using PI Asset Fram…
- CVE-2016-8366Webvisit in Phoenix Contact ILC PLCs offers a password macro…
- CVE-2016-8368An issue was discovered in Mitsubishi Electric Automation ME…8.6
- CVE-2016-8369An issue was discovered in Lynxspring JENEsys BAS Bridge ver…
- CVE-2016-8370An issue was discovered in Mitsubishi Electric Automation ME…7.5
- CVE-2016-8371The web server in Phoenix Contact ILC PLCs can be accessed w…
- CVE-2016-8372An issue was discovered in Moxa ioLogik E1210, firmware Vers…8.1
- CVE-2016-8374An issue was discovered in Schneider Electric Magelis HMI Ma…7.5
Are you affected by CVE-2016-8367?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
