CVE-2016-4784
A vulnerability has been identified in firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01.
Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00.
Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03.
Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21.
EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02.
SIPROTEC 7SJ686 : All versions < V 4.83.
SIPROTEC 7UT686 : All versions < V 4.01.
SIPROTEC 7SD686 : All versions < V 4.03.
SIPROTEC 7SJ66 : All versions < V 4.20. The integrated web server (port 80/tcp) of the affected devices could allow remote attackers to obtain sensitive device information if network access was obtained.
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
ATT&CK techniques
20Techniques this CVE enables - linked via CWECAPECATT&CK. High◆ = named directly in ATT&CK or Nuclei templates.
CAPEC attack patterns
12Attack patterns this CVE enables - the bridge from weakness to ATT&CK technique.