CVE-2016-9155
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
22/11/2016
Last modified:
12/04/2025
Description
The following SIEMENS branded IP Camera Models CCMW3025, CVMW3025-IR, CFMW3025 prior to version 1.41_SP18_S1; CCPW3025, CCPW5025 prior to version 0.1.73_S1; CCMD3025-DN18 prior to version v1.394_S1; CCID1445-DN18, CCID1445-DN28, CCID1145-DN36, CFIS1425, CCIS1425, CFMS2025, CCMS2025, CVMS2025-IR, CFMW1025, CCMW1025 prior to version v2635_SP1 could allow an attacker with network access to the web server to obtain administrative credentials under certain circumstances.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:siemens:ccid1445-dn18_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:ccid1445-dn28_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:ccid1445-dn36_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:ccis1425_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:ccmd3025-dn18_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:ccms2025_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:ccmw1025_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:ccmw3025_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:ccpw3025_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:cfis1425_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:cfms2025_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:cfmw1025_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:cfmw3025_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:cvms2025-ir_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:cvmw3025-ir_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.securityfocus.com/bid/94392
- https://ics-cert.us-cert.gov/advisories/ICSA-16-322-01
- https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-284765.pdf
- http://www.securityfocus.com/bid/94392
- https://ics-cert.us-cert.gov/advisories/ICSA-16-322-01
- https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-284765.pdf



