CVE-2016-8563
published 2016-10-13CVE-2016-8563: Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to cause a denial of service (ALM service outage) via crafted packets…
PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.99%
85.8th percentile
Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to cause a denial of service (ALM service outage) via crafted packets to TCP port 4410.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | automation_license_manager | <= 5.3 | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens Automation License Manager Vulnerabilities
cisa_ics·2016-10-13
Siemens Automation License Manager Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Automation License Manager Vulnerabilities
Last RevisedOctober 13, 2016
Alert CodeICSA-16-287-02
## OVERVIEW
Siemens has identified vulnerabilities in Siemen’s Automation License Manager (ALM). These vulnerabilities were reported directly to Siemens by Sergey Temnikov and Vladimir Dashchenko from Critical Infrastructure Defence Team, Kaspersky Lab. Siemens has produced a new version to mitigate these vulnerabilities.
These vulnerabilities could be exploited remotely.
## AFFECTED PRODUCTS
Siemens reports that the vulnerabilities affect the following versions of ALM:
-
GHSA
GHSA-q9gx-mx48-xpg2: Siemens Automation License Manager (ALM) before 5
ghsa_unreviewed·2022-05-17
CVE-2016-8563 [HIGH] CWE-20 GHSA-q9gx-mx48-xpg2: Siemens Automation License Manager (ALM) before 5
Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to cause a denial of service (ALM service outage) via crafted packets to TCP port 4410.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/93553http://www.securitytracker.com/id/1037011http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-284342.pdfhttps://ics-cert.us-cert.gov/advisories/ICSA-16-287-02http://www.securityfocus.com/bid/93553http://www.securitytracker.com/id/1037011http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-284342.pdfhttps://ics-cert.us-cert.gov/advisories/ICSA-16-287-02
2016-10-13
Published