CVE-2016-9154 Information
Description
Siemens Desigo PX Web modules PXA40-W0 PXA40-W1 PXA40-W2 for Desigo PX automation controllers PXC00-E.D PXC50-E.D PXC100-E.D PXC200-E.D (All firmware versions V6.00.046) and Desigo PX Web modules PXA30-W0 PXA30-W1 PXA30-W2 for Desigo PX automation controllers PXC00-U PXC64-U PXC128-U (All firmware versions V6.00.046) use a pseudo random number generator with insufficient entropy to generate certificates for HTTPS potentially allowing remote attackers to reconstruct the corresponding private key.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
http://www.securityfocus.com/bid/94962 http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-856492.pdf https://ics-cert.us-cert.gov/advisories/ICSA-16-355-01
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: