← Vulnerability feed

Vulnerability record · CVE-2016-8562 · published 18 November 2016

CVE-2016-8562: Siemens SIMATIC CP 1543-1 SNMP write access allows denial of service

Siemens · Simatic Cp 1543 1 Firmware

SIMATIC CP 1543-1 and SIPLUS NET CP 1543-1 firmware before V2.0.28 permits writes to SNMP variables on port 161/udp that should be read-only and configurable only through TIA-Portal. Writing these variables can reduce availability or cause a denial-of-service on the affected communications processor.

7.5 CVSS 3.1 High CISA KEV since 3 Mar 2022 EPSS 3.6% · top 10.9%
7.5CVSS 3.1 base score, v2 3.5
3.6%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
9References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special conditions it was possible to write SNMP variables on port 161/udp which should be read-only and should only be configured with TIA-Portal. A write to these variables could reduce the availability or cause a denial-of-service.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is in CISA KEV with known exploitation and a CVSS score of 7.5, though exploitation requires high complexity and low privileges.

What it is

SIMATIC CP 1543-1 and SIPLUS NET CP 1543-1 firmware before V2.0.28 permits writes to SNMP variables on port 161/udp that should be read-only and configurable only through TIA-Portal. Writing these variables can reduce availability or cause a denial-of-service on the affected communications processor.

Impact

An attacker can modify protected SNMP variables, degrading availability or causing a denial-of-service on the device. The CVSS vector also indicates high confidentiality and integrity impact, though the description only details availability effects.

Attack surface

Reachable over the network via SNMP on port 161/udp; the CVSS vector requires low privileges (PR:L) and no user interaction, with high attack complexity.

Exploitation

CVE-2016-8562 is listed in CISA KEV (added 2022-03-03), indicating known exploitation, while EPSS is 0.03624 (89th percentile); no ransomware campaign use is documented.

What to do

  • Upgrade SIMATIC CP 1543-1 and SIPLUS NET CP 1543-1 firmware to V2.0.28 or later per Siemens advisory SSA-672373.
  • Restrict network access to SNMP port 161/udp on affected devices using firewalls or segmentation.
  • Disable SNMP or restrict SNMP write access where the device configuration allows.
  • Monitor Siemens and CISA advisories for updated guidance on this CVE.

Detection

  • Monitor network traffic for SNMP write operations (SetRequest) to port 161/udp on affected CP 1543-1 devices.
  • Alert on unexpected SNMP configuration changes or device availability loss on these communications processors.
  • Review device logs for SNMP-related errors or restarts that could indicate exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-8562 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-8562 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2022-34819Siemens simatic cp 1242-7 v2 firmware heap-based buffer overflow vulnerabilityA vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 L…EPSS 2.0%9.8CVE-2019-12815ProFTPD mod_copy arbitrary file copy enables unauthenticated RCEmod_copy in ProFTPD up to 1.3.5b performs an arbitrary file copy without validating the source or destination, letting an unauthenticated remote clie…EPSS 58%analysed8.8CVE-2022-34821Siemens simatic cp 1242-7 v2 firmware code injection vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2), SCALANCE …EPSS 2.4%8.7CVE-2024-50310Siemens simatic cp 1543-1 firmware incorrect authorization vulnerabilityA vulnerability has been identified in SIMATIC CP 1543-1 V4.0 (6GK7543-1AX10-0XE0) (All versions >= V4.0.44 < V4.0.50). Affected devices do not prope…EPSS 0.48%8.4CVE-2022-34820Siemens simatic cp 1242-7 v2 firmware command injection vulnerabilityA vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 L…EPSS 2.2%7.5CVE-2021-41991Strongswan integer overflow vulnerabilityThe in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to …EPSS 5.3%7.1CVE-2017-2681Siemens simatic cp 343-1 std firmware uncontrolled resource consumption vulnerabilitySpecially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of…EPSS 0.91%7.1CVE-2017-2680Siemens simatic cp 343-1 std firmware uncontrolled resource consumption vulnerabilitySpecially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2)…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2016-8562), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.