CVE-2016-9154 Information

Description

Siemens Desigo PX Web modules PXA40-W0 PXA40-W1 PXA40-W2 for Desigo PX automation controllers PXC00-E.D PXC50-E.D PXC100-E.D PXC200-E.D (All firmware versions V6.00.046) and Desigo PX Web modules PXA30-W0 PXA30-W1 PXA30-W2 for Desigo PX automation controllers PXC00-U PXC64-U PXC128-U (All firmware versions V6.00.046) use a pseudo random number generator with insufficient entropy to generate certificates for HTTPS potentially allowing remote attackers to reconstruct the corresponding private key.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Reference

http://www.securityfocus.com/bid/94962 http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-856492.pdf https://ics-cert.us-cert.gov/advisories/ICSA-16-355-01

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

7.5

Share on: