← Vulnerability feed

Vulnerability record · CVE-2016-8672 · published 23 November 2016

CVE-2016-8672: Siemens simatic cp 343-1 firmware information exposure vulnerability

Siemens · Simatic Cp 343 1 Firmware

A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.2.17), SIMATIC S7-300 PN/DP CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP CPU family (incl. SIPLUS variants) (All versions). The integrated web server delivers cookies without the "secure" flag. Modern browsers interpreting the flag would mitigate potential data leakage in case of clear text transmission.

5.3 CVSS 3.0 Medium EPSS 1.9% · top 21.7% CWE-200 · Information exposure
5.3CVSS 3.0 base score, v2 5.0
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.2.17), SIMATIC S7-300 PN/DP CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP CPU family (incl. SIPLUS variants) (All versions). The integrated web server delivers cookies without the "secure" flag. Modern browsers interpreting the flag would mitigate potential data leakage in case of clear text transmission.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-8672 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.7CVE-2015-8214Siemens simatic cp 443-1 firmware permissions and access controls vulnerabilityA vulnerability has been identified in SIMATIC NET CP 342-5 (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Advanced (incl. SIPLUS varia…EPSS 2.1%8.8CVE-2016-8673Siemens simatic s7 300 cpu firmware cross-site request forgery vulnerabilityA vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl…EPSS 1.1%7.5CVE-2023-51440Siemens simatic cp 343-1 firmware vulnerabilityA vulnerability has been identified in SIMATIC CP 343-1 (6GK7343-1EX30-0XE0) (All versions), SIMATIC CP 343-1 Lean (6GK7343-1CX10-0XE0) (All versions…EPSS 0.60%7.5CVE-2022-43716Siemens simatic cp 1242-7 v2 firmware use after free vulnerabilityA vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (Al…EPSS 0.95%7.5CVE-2022-43767Siemens simatic cp 1242-7 v2 firmware vulnerabilityA vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (Al…EPSS 0.72%7.5CVE-2022-43768Siemens simatic cp 1242-7 v2 firmware allocation without limits vulnerabilityA vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (Al…EPSS 0.95%7.5CVE-2021-33737Siemens simatic cp 343-1 firmware memory buffer overflow vulnerabilityA vulnerability has been identified in SIMATIC CP 343-1 (incl. SIPLUS variants) (All versions), SIMATIC CP 343-1 Advanced (incl. SIPLUS variants) (Al…EPSS 1.1%7.5CVE-2019-19301Siemens scalance xc-200 firmware uncontrolled resource consumption vulnerabilityA vulnerability has been identified in SCALANCE X200-4P IRT, SCALANCE X201-3P IRT, SCALANCE X201-3P IRT PRO, SCALANCE X202-2IRT, SCALANCE X202-2P IRT…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2016-8672), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.