Vulnerability record · CVE-2016-8562 · published 18 November 2016
CVE-2016-8562: Siemens SIMATIC CP 1543-1 SNMP write access allows denial of service
Siemens · Simatic Cp 1543 1 Firmware
SIMATIC CP 1543-1 and SIPLUS NET CP 1543-1 firmware before V2.0.28 permits writes to SNMP variables on port 161/udp that should be read-only and configurable only through TIA-Portal. Writing these variables can reduce availability or cause a denial-of-service on the affected communications processor.
Description
A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special conditions it was possible to write SNMP variables on port 161/udp which should be read-only and should only be configured with TIA-Portal. A write to these variables could reduce the availability or cause a denial-of-service.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in CISA KEV with known exploitation and a CVSS score of 7.5, though exploitation requires high complexity and low privileges.
What it is
SIMATIC CP 1543-1 and SIPLUS NET CP 1543-1 firmware before V2.0.28 permits writes to SNMP variables on port 161/udp that should be read-only and configurable only through TIA-Portal. Writing these variables can reduce availability or cause a denial-of-service on the affected communications processor.
Impact
An attacker can modify protected SNMP variables, degrading availability or causing a denial-of-service on the device. The CVSS vector also indicates high confidentiality and integrity impact, though the description only details availability effects.
Attack surface
Reachable over the network via SNMP on port 161/udp; the CVSS vector requires low privileges (PR:L) and no user interaction, with high attack complexity.
Exploitation
CVE-2016-8562 is listed in CISA KEV (added 2022-03-03), indicating known exploitation, while EPSS is 0.03624 (89th percentile); no ransomware campaign use is documented.
What to do
- Upgrade SIMATIC CP 1543-1 and SIPLUS NET CP 1543-1 firmware to V2.0.28 or later per Siemens advisory SSA-672373.
- Restrict network access to SNMP port 161/udp on affected devices using firewalls or segmentation.
- Disable SNMP or restrict SNMP write access where the device configuration allows.
- Monitor Siemens and CISA advisories for updated guidance on this CVE.
Detection
- Monitor network traffic for SNMP write operations (SetRequest) to port 161/udp on affected CP 1543-1 devices.
- Alert on unexpected SNMP configuration changes or device availability loss on these communications processors.
- Review device logs for SNMP-related errors or restarts that could indicate exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-8562 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/94436 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-672373.pdf | Broken LinkPatchVendor Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-672373.pdf | Vendor Advisory |
| https://ics-cert.us-cert.gov/advisories/ICSA-16-327-01 | Third Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/94436 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-672373.pdf | Broken LinkPatchVendor Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-672373.pdf | Vendor Advisory |
| https://ics-cert.us-cert.gov/advisories/ICSA-16-327-01 | Third Party AdvisoryUS Government Resource |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-8562 | US Government Resource |
Track CVE-2016-8562 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-8562), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.