CVE-2016-8672
Last modified
CVE-2016-8672 is a vulnerability of currently unknown severity. A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl. EPSS estimates a 1.85% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.2.17), SIMATIC S7-300 PN/DP CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP CPU family (incl. SIPLUS variants) (All versions). The integrated web server delivers cookies without the "secure" flag. Modern browsers interpreting the flag would mitigate potential data leakage in case of clear text transmission.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Simatic Cp 343-1 Firmware | All versions |
| Siemens | Simatic S7 300 Cpu Firmware | All versions |
| Siemens | Simatic S7 400 Cpu Firmware | All versions |
| Siemens | Simatic Cp 443-1 Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-8672?
How severe is CVE-2016-8672?
How do I fix CVE-2016-8672?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-8666The IP stack in the Linux kernel before 4.6 allows remote at…7.5
- CVE-2016-8667The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Qu…6
- CVE-2016-8668The rocker_io_writel function in hw/net/rocker/rocker.c in Q…6
- CVE-2016-8669The serial_update_parameters function in hw/char/serial.c in…6
- CVE-2016-8670Integer signedness error in the dynamicGetbuf function in gd…
- CVE-2016-8671The pstm_exptmod function in MatrixSSL 3.8.6 and earlier doe…
- CVE-2016-8673A vulnerability has been identified in SIMATIC CP 343-1 Adva…
- CVE-2016-8674The pdf_to_num function in pdf-object.c in MuPDF before 1.10…
- CVE-2016-8675The get_vlc2 function in get_bits.h in Libav before 11.9 all…
- CVE-2016-8676The get_vlc2 function in get_bits.h in Libav 11.9 allows rem…
- CVE-2016-8677The AcquireQuantumPixels function in MagickCore/quantum.c in…8.8
- CVE-2016-8678The IsPixelMonochrome function in MagickCore/pixel-accessor.…
Are you affected by CVE-2016-8672?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
