CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
Percentile
76.8%
CVSS v3 5.3
ATTENTION: Exploitable remotely/low skill level to exploit
Vendor: Siemens
Equipment: SIPROTEC 4 and SIPROTEC Compact
Vulnerabilities: Information Exposure
This updated advisory is a follow-up to the updated advisory titled ICSA-16-140-02 Siemens SIPROTEC Information Disclosure Vulnerabilities (Update A) that was published July 5, 2016, on the NCCIC/ICS-CERT website.
Exploits of these vulnerabilities could allow an attacker with network access to obtain sensitive device information.
--------- Begin Update B Part 1 of 1 --------
Siemens reports that the vulnerabilities affect the following products:
--------- End Update B Part 1 of 1 ----------
The integrated web server (Port 80/TCP) of the affected devices could allow remote attackers to obtain sensitive device information if network access was obtained.
CVE-2016-4784 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
The integrated web server (Port 80/TCP) of the affected devices could allow remote attackers to obtain a limited amount of device memory content if network access was obtained. This vulnerability only affects EN100 Ethernet module included in SIPROTEC 4 and SIPROTEC Compact devices.
CVE-2016-4785 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Aleksandr Bersenev from HackerDom team and Pavel Toporkov from Kaspersky Lab reported these vulnerabilities to Siemens.
Siemens provides firmware update V4.27 for EN100 module included in SIPROTEC 4 and SIPROTEC Compact to fix the vulnerabilities. The firmware updates can be found at the following locations on the Siemens website:
<http://www.siemens.com/downloads/siprotec-4>
<http://www.siemens.com/downloads/siprotec-compact>
For SIPROTEC Compact 7SJ80 with Ethernet Service Interface on Port A, Siemens provides firmware update V4.76. The firmware update can be found at the following location on the Siemens website:
<http://www.siemens.com/downloads/siprotec-compact>
An attacker must have network access to the affected devices. For remaining affected products, Siemens recommends to protect network access with appropriate mechanisms (e.g., firewalls, segmentation, VPN). It is advised to configure the environment according to Siemens operational guidelines in order to run the devices in a protected IT environment. Siemens provides guidance at the following location for operating the devices only within trusted networks:
<http://www.siemens.com/gridsecurity>
For more information on these vulnerabilities and more detailed mitigation instructions, please see Siemens Security Advisory SSA-547990 at the following location:
<http://www.siemens.com/cert/advisories>
NCCIC recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Specifically, users should:
NCCIC reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
NCCIC also provides a section for control systems security recommended practices on the ICS-CERT web page. Several recommended practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
Additional mitigation guidance and recommended practices are publicly available on the ICS-CERT website in the Technical Information Paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing any suspected malicious activity should follow their established internal procedures and report their findings to NCCIC for tracking and correlation against other incidents.
No known public exploits specifically target these vulnerabilities.
cwe.mitre.org/data/definitions/200.html
cwe.mitre.org/data/definitions/200.html
web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-4784
web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-4785
www.siemens.com/cert/advisories
www.siemens.com/downloads/siprotec-4
www.siemens.com/downloads/siprotec-compact
www.siemens.com/downloads/siprotec-compact
www.siemens.com/gridsecurity
cisasurvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?product=https://www.cisa.gov/news-events/ics-advisories/icsa-16-140-02
public.govdelivery.com/accounts/USDHSCISA/subscriber/new?topic_id=USDHSCISA_138
twitter.com/CISAgov
twitter.com/intent/tweet?text=Siemens%20SIPROTEC%20Information%20Disclosure%20Vulnerabilities%20%28Update%20B%29+https://www.cisa.gov/news-events/ics-advisories/icsa-16-140-02
www.dhs.gov
www.dhs.gov/foia
www.dhs.gov/performance-financial-reports
www.facebook.com/CISA
www.facebook.com/sharer/sharer.php?u=https://www.cisa.gov/news-events/ics-advisories/icsa-16-140-02&title=Siemens%20SIPROTEC%20Information%20Disclosure%20Vulnerabilities%20%28Update%20B%29
www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
www.instagram.com/cisagov
www.linkedin.com/company/cybersecurity-and-infrastructure-security-agency
www.linkedin.com/sharing/share-offsite/?url=https://www.cisa.gov/news-events/ics-advisories/icsa-16-140-02
www.oig.dhs.gov/
www.usa.gov/
www.whitehouse.gov/
www.youtube.com/@cisagov
mailto:?subject=Siemens%20SIPROTEC%20Information%20Disclosure%20Vulnerabilities%20%28Update%20B%29&body=www.cisa.gov/news-events/ics-advisories/icsa-16-140-02
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
Percentile
76.8%