An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected devices could allow unauthenticated remote attackers to obtain sensitive device information over the network.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-164516.pdf | mitigation vendor advisory |
http://www.securityfocus.com/bid/101884 | vdb entry third party advisory |