5.3
CVSSv3

CVE-2017-12737

Published: 15/11/2017 Updated: 30/11/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected devices could allow unauthenticated remote malicious users to obtain sensitive device information over the network.

Vulnerable Product Search on Vulmon Subscribe to Product

siemens sm-2556_firmware enos00

siemens sm-2556_firmware eta2

siemens sm-2556_firmware etls00

siemens sm-2556_firmware modi00

siemens sm-2556_firmware dnpi00

siemens sm-2556_firmware erac00

Exploits

Siemens SICAM RTUs SM-2556 COM modules (firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00) suffer from authentication bypass, code execution, and cross site scripting vulnerabilities ...