CVE-2016-8374
Last modified
CVE-2016-8374 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe). An attacker may be able to disrupt a targeted web server, resulting in a denial of service because of UNCONTROLLED RESOURCE CONSUMPTION.. EPSS estimates a 2.16% chance of exploitation in the next 30 days.
Description
An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe). An attacker may be able to disrupt a targeted web server, resulting in a denial of service because of UNCONTROLLED RESOURCE CONSUMPTION.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Magelis Gtu Universal Panel Firmware | All versions |
| Schneider-Electric | Magelis Gto Advanced Optimum Panel Firmware | All versions |
| Schneider-Electric | Magelis Sto5 Small Panel Firmware | All versions |
| Schneider-Electric | Magelis Stu Small Panel Firmware | All versions |
| Schneider-Electric | Magelis Xbt Gh Advanced Hand-Held Panel Firmware | All versions |
| Schneider-Electric | Magelis Xbt Gk Advanced Touchscreen Panel With Keyboard Firmware | All versions |
| Schneider-Electric | Magelis Xbt Gt Advanced Touchscreen Panel Firmware | All versions |
| Schneider-Electric | Magelis Xbt Gtw Advanced Open Touchscreen Panel Firmware | All versions |
References
- http://www.securityfocus.com/bid/94093Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-308-02Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/94093Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-308-02Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-8374?
How severe is CVE-2016-8374?
How do I fix CVE-2016-8374?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-8367An issue was discovered in Schneider Electric Magelis HMI Ma…5.3
- CVE-2016-8368An issue was discovered in Mitsubishi Electric Automation ME…8.6
- CVE-2016-8369An issue was discovered in Lynxspring JENEsys BAS Bridge ver…
- CVE-2016-8370An issue was discovered in Mitsubishi Electric Automation ME…7.5
- CVE-2016-8371The web server in Phoenix Contact ILC PLCs can be accessed w…
- CVE-2016-8372An issue was discovered in Moxa ioLogik E1210, firmware Vers…8.1
- CVE-2016-8375An issue was discovered in Becton, Dickinson and Company (BD…
- CVE-2016-8376An issue was discovered in Kabona AB WebDatorCentral (WDC) a…
- CVE-2016-8377An issue was discovered in Fatek Automation PLC WinProladder…8
- CVE-2016-8378An issue was discovered in Lynxspring JENEsys BAS Bridge ver…
- CVE-2016-8379An issue was discovered in Moxa ioLogik E1210, firmware Vers…8.1
- CVE-2016-8380The web server in Phoenix Contact ILC PLCs allows access to …
Are you affected by CVE-2016-8374?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
