CVE-2016-5743

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
22/07/2016
Last modified:
12/04/2025

Description

Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Update 9 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.1 Update 3 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.2 Update 1 as distributed in SIMATIC PCS 7 8.2, and SIMATIC WinCC Runtime Professional before 13 SP1 Update 9 allow remote attackers to execute arbitrary code via crafted packets.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:siemens:simatic_batch:*:*:*:*:*:*:*:* 7.1 (including)
cpe:2.3:a:siemens:simatic_wincc:*:*:*:*:*:*:*:* 7.3 (including)
cpe:2.3:a:siemens:simatic_wincc:*:*:*:*:*:*:*:* 7.4 (including)
cpe:2.3:a:siemens:simatic_pcs_7:*:sp1:*:*:*:*:*:* 8.1 (including)
cpe:2.3:a:siemens:simatic_openpcs_7:*:*:*:*:*:*:*:* 8.1 (including)
cpe:2.3:a:siemens:simatic_pcs_7:*:sp1:*:*:*:*:*:* 8.1 (including)
cpe:2.3:a:siemens:simatic_openpcs_7:*:*:*:*:*:*:*:* 8.2 (including)
cpe:2.3:a:siemens:simatic_pcs_7:*:*:*:*:*:*:*:* 8.2 (including)
cpe:2.3:a:siemens:simatic_wincc_runtime_professional:*:sp1:*:*:*:*:*:* 13 (including)