CVE-2016-8374
Last modified
CVE-2016-8374 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe). An attacker may be able to disrupt a targeted web server, resulting in a denial of service because of UNCONTROLLED RESOURCE CONSUMPTION.. EPSS estimates a 2.16% chance of exploitation in the next 30 days.
Description
An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe). An attacker may be able to disrupt a targeted web server, resulting in a denial of service because of UNCONTROLLED RESOURCE CONSUMPTION.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Magelis Gtu Universal Panel Firmware | All versions |
| Schneider-Electric | Magelis Gto Advanced Optimum Panel Firmware | All versions |
| Schneider-Electric | Magelis Sto5 Small Panel Firmware | All versions |
| Schneider-Electric | Magelis Stu Small Panel Firmware | All versions |
| Schneider-Electric | Magelis Xbt Gh Advanced Hand-Held Panel Firmware | All versions |
| Schneider-Electric | Magelis Xbt Gk Advanced Touchscreen Panel With Keyboard Firmware | All versions |
| Schneider-Electric | Magelis Xbt Gt Advanced Touchscreen Panel Firmware | All versions |
| Schneider-Electric | Magelis Xbt Gtw Advanced Open Touchscreen Panel Firmware | All versions |
References
- http://www.securityfocus.com/bid/94093Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-308-02Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/94093Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-308-02Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-8374?
How severe is CVE-2016-8374?
How do I fix CVE-2016-8374?
Are you affected by CVE-2016-8374?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
