U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2016-8672

Change History

CVE Modified by MITRE 12/12/2019 2:15:12 PM

Action Type Old Value New Value
Added CWE

								
							
							
						
Siemens AG CWE-614
Changed Description
The integrated web server on Siemens SIMATIC CP 343-1 Advanced prior to version 3.0.53, SIMATIC CP 443-1 Advanced prior to version 3.2.17, SIMATIC S7-300 CPU, and SIMATIC S7-400 CPU devices does not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.
A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.2.17), SIMATIC S7-300 PN/DP CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP CPU family (incl. SIPLUS variants) (All versions). The integrated web server delivers cookies without the "secure" flag. Modern browsers interpreting the flag would mitigate potential data leakage in case of clear text transmission.
Removed Reference
http://www.securityfocus.com/bid/94460 [Third Party Advisory, VDB Entry]

								
						
Removed Reference
http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-603476.pdf [Vendor Advisory]

								
						
Removed Reference
https://ics-cert.us-cert.gov/advisories/ICSA-16-327-02 [No Types Assigned]