Skip to main content

CVE-2016-8562

7.5
HIGHCVSS v3.1 Base Score
18.55%
LOW RiskEPSS (95th percentile)
KEV
NVD-CWE-noinfo

A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special conditions it was possible to write SNMP variables on port 161/udp which should be read-only and should only be configured with TIA-Portal. A write to these variables could reduce the availability or cause a denial-of-service.

Published: 11/18/2016
Modified: 4/21/2026
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability

Vendor / Product:

Siemens SIMATIC CP

Required Action:

Apply updates per vendor instructions.

Due Date: 3/24/2022(OVERDUE)
Added to KEV:

3/3/2022

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2016-8562

Vulnerability Summary

CVSS v3 Score

7.5HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

3.5

AV:N/AC:M/Au:S/C:N/I:N/A:P

EPSS Score (Exploitation Probability)

18.55%LOW Exploitation Risk
95th percentile

This vulnerability has a 18.55% probability of being exploited in the next 30 days, ranking higher than 95% of all scored CVEs.

CWE Classification

NVD-CWE-noinfo

Related Vulnerabilities