« Volver al listado

CVE-2017-12739

Estado: ModificadaCrítica (9.8)—

An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected devices could allow unauthenticated remote attackers to execute arbitrary code on the affected device.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-12739",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": true,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "productcert@siemens.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00",
          "versions": [
            {
              "status": "affected",
              "version": "Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-11-15T08:29:00.297",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/101884",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "productcert@siemens.com"
    },
    {
      "url": "https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-164516.pdf",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "productcert@siemens.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/101884",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-164516.pdf",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1188"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected devices could allow unauthenticated remote attackers to execute arbitrary code on the affected device."
    },
    {
      "lang": "es",
      "value": "Se ha descubierto un problema en los módulos SM-2556 COM de las unidades terminal remotas SICAM de Siemens con las variantes de firmware ENOS00, ERAC00, ETA2, ETLS00, MODi00 y DNPi00. El servidor web integrado (puerto 80/tcp) de los dispositivos afectados podría permitir que los atacantes remotos no autenticados ejecuten código arbitrario en el dispositivo afectado."
    }
  ],
  "lastModified": "2026-06-17T01:03:52.887",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:sm-2556_firmware:dnpi00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED5101E6-6539-4764-AA69-04F231B579F3"
            },
            {
              "criteria": "cpe:2.3:o:siemens:sm-2556_firmware:enos00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E03424AF-2BF9-4F1D-98A2-A98D9D413ACF"
            },
            {
              "criteria": "cpe:2.3:o:siemens:sm-2556_firmware:erac00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "407642BA-53E7-4D3E-8068-0817BB490953"
            },
            {
              "criteria": "cpe:2.3:o:siemens:sm-2556_firmware:eta2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "972FB974-D711-475F-88F1-5617929D7319"
            },
            {
              "criteria": "cpe:2.3:o:siemens:sm-2556_firmware:etls00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80F5FF04-9652-464E-A7CB-490538BE26E2"
            },
            {
              "criteria": "cpe:2.3:o:siemens:sm-2556_firmware:modi00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B8337D2-8A9C-4554-8B2C-808F59D7F35B"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:sm-2556:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1D7A2477-9462-47A8-A91F-8771F82B6615"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "productcert@siemens.com"
}