A vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl
Published Dec 17, 2016
7.5
HIGHCVSS 3.1
EPSS 3.03%
Description
A vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V6 and below CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 V6 and earlier CPU family (All versions), SIMATIC S7-400 V7 CPU family (All versions). Specially crafted packets sent to port 80/tcp could cause the affected devices to go into defect mode. A cold restart is required to recover the system.
Affected products
-
- Version All versionsStatusaffectedConstraints-
- Version
- Vendor Siemens AG Product SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) Defaultn/a
- Version All versionsStatusaffectedConstraints-
- Version
- Vendor Siemens AG Product SIMATIC S7-400 PN/DP V6 and below CPU family (incl. SIPLUS variants) Defaultn/a
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Siemens AG | SIMATIC S7-300 CPU family | n/a |
| ||||||
| Siemens AG | SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) | n/a |
| ||||||
| Siemens AG | SIMATIC S7-400 PN/DP V6 and below CPU family (incl. SIPLUS variants) | n/a |
| ||||||
| Siemens AG | SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants) | n/a |
| ||||||
| Siemens AG | SIMATIC S7-400 V6 and earlier CPU family | n/a |
| ||||||
| Siemens AG | SIMATIC S7-400 V7 CPU family | n/a |
|
Configuration 1
- n/a
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 2
- n/a
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jun 2, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.03% (0.03027) | 87.01th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.00% (0.03002) | 85.59th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.15% (0.01146) | 76.52th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.17% (0.02173) | 73.84th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.15% (0.01146) | 76.99th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.37% (0.00373) | 73.56th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.37% (0.00373) | 71.92th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.37% (0.00373) | 68.40th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Sep 10, 2022 | 1.02% (0.01018) | 38.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.02% (0.01018) | 36.86th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.02% (0.01018) | 19.50th | v2 (v2022.01.01) |
References (5)
- http://www.securityfocus.com/bid/94820 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1037434 vdb-entryx_refsource_SECTRACK
- https://cert-portal.siemens.com/productcert/pdf/ssa-731239.pdf x_refsource_MISC
- https://ics-cert.us-cert.gov/advisories/ICSA-16-348-05 x_refsource_MISC
- https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-731239.pdf x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/94820 | vdb-entryx_refsource_BID | |
| http://www.securitytracker.com/id/1037434 | vdb-entryx_refsource_SECTRACK | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-731239.pdf | x_refsource_MISC | |
| https://ics-cert.us-cert.gov/advisories/ICSA-16-348-05 | x_refsource_MISC | |
| https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-731239.pdf | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.