9.8
CVSSv3

CVE-2017-12739

Published: 15/11/2017 Updated: 03/10/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected devices could allow unauthenticated remote malicious users to execute arbitrary code on the affected device.

Vulnerable Product Search on Vulmon Subscribe to Product

siemens sm-2556_firmware enos00

siemens sm-2556_firmware erac00

siemens sm-2556_firmware eta2

siemens sm-2556_firmware etls00

siemens sm-2556_firmware modi00

siemens sm-2556_firmware dnpi00

Exploits

Siemens SICAM RTUs SM-2556 COM modules (firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00) suffer from authentication bypass, code execution, and cross site scripting vulnerabilities ...