ID

VAR-201611-0334


CVE

CVE-2016-9155


TITLE

plural SIEMENS Brand IP Vulnerability to obtain administrator credentials in camera products

Trust: 0.8

sources: JVNDB: JVNDB-2016-005924

DESCRIPTION

The following SIEMENS branded IP Camera Models CCMW3025, CVMW3025-IR, CFMW3025 prior to version 1.41_SP18_S1; CCPW3025, CCPW5025 prior to version 0.1.73_S1; CCMD3025-DN18 prior to version v1.394_S1; CCID1445-DN18, CCID1445-DN28, CCID1145-DN36, CFIS1425, CCIS1425, CFMS2025, CCMS2025, CVMS2025-IR, CFMW1025, CCMW1025 prior to version v2635_SP1 could allow an attacker with network access to the web server to obtain administrative credentials under certain circumstances. Supplementary information : CWE Vulnerability type by CWE-284: Improper Access Control ( Inappropriate access control ) Has been identified. CCMW3025, CVMW3025-IR, CFMW3025, CCPW3025, etc. are IP camera products of SIEMENS. An information disclosure vulnerability exists in SIEMENS-brandedIP-basedCCTVcameras. Multiple Siemens IP CCTV Cameras are prone to an information disclosure vulnerability. Successful exploits may lead to other attacks. The following device models and versions are affected: CCMW3025 prior to 1.41_SP18_S1, CVMW3025-IR prior to 1.41_SP18_S1, CFMW3025 prior to 1.41_SP18_S1, CCPW3025 prior to 0.1.73_S1, CCPW5025 prior to 0.1.73_S1, CCMD18025-DN18025 Versions prior to v1.394_S1, CCID1445-DN18 prior to v2635, CCID1445-DN28 prior to v2635, CCID1445-DN36 prior to v2635, CFIS1425 prior to v2635, CCIS1425 prior to v2635, CFMS2025 prior to v2635, CCMS2025 Versions prior to v2635, versions prior to CVMS2025-IR v2635, versions prior to CFMW1025 v2635, versions prior to CCMW1025 2635

Trust: 2.52

sources: NVD: CVE-2016-9155 // JVNDB: JVNDB-2016-005924 // CNVD: CNVD-2016-11370 // BID: 94392 // VULHUB: VHN-97975

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['camera device']sub_category:IP camera

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2016-11370

AFFECTED PRODUCTS

vendor:siemensmodel:ccpw3025scope:eqversion: -

Trust: 1.6

vendor:siemensmodel:ccmd3025-dn18scope:eqversion: -

Trust: 1.6

vendor:siemensmodel:ccid1445-dn18scope:eqversion: -

Trust: 1.6

vendor:siemensmodel:ccmw3025scope:eqversion: -

Trust: 1.6

vendor:siemensmodel:ccis1425scope:eqversion: -

Trust: 1.6

vendor:siemensmodel:ccid1445-dn36scope:eqversion: -

Trust: 1.6

vendor:siemensmodel:cfis1425scope:eqversion: -

Trust: 1.6

vendor:siemensmodel:cvmw3025-irscope:eqversion: -

Trust: 1.6

vendor:siemensmodel:ccid1445-dn28scope:eqversion: -

Trust: 1.6

vendor:siemensmodel:cfmw3025scope:eqversion: -

Trust: 1.6

vendor:siemensmodel:ccid1445-dn18scope:ltversion:2635

Trust: 1.4

vendor:siemensmodel:ccid1445-dn28scope:ltversion:2635

Trust: 1.4

vendor:siemensmodel:ccid1445-dn36scope:ltversion:2635

Trust: 1.4

vendor:siemensmodel:cfis1425scope:ltversion:2635

Trust: 1.4

vendor:siemensmodel:ccis1425scope:ltversion:2635

Trust: 1.4

vendor:siemensmodel:cfms2025scope:ltversion:2635

Trust: 1.4

vendor:siemensmodel:ccms2025scope:ltversion:2635

Trust: 1.4

vendor:siemensmodel:cvms2025-irscope:ltversion:2635

Trust: 1.4

vendor:siemensmodel:cfmw1025scope:ltversion:2635

Trust: 1.4

vendor:siemensmodel:ccmw1025scope:ltversion:2635

Trust: 1.4

vendor:siemensmodel:cfmw1025scope:eqversion: -

Trust: 1.0

vendor:siemensmodel:ccmw1025scope:eqversion: -

Trust: 1.0

vendor:siemensmodel:cvms2025-irscope:eqversion: -

Trust: 1.0

vendor:siemensmodel:cfms2025scope:eqversion: -

Trust: 1.0

vendor:siemensmodel:ccms2025scope:eqversion: -

Trust: 1.0

vendor:siemensmodel:ccid1445-dn18scope: - version: -

Trust: 0.8

vendor:siemensmodel:ccid1445-dn28scope: - version: -

Trust: 0.8

vendor:siemensmodel:ccid1445-dn36scope: - version: -

Trust: 0.8

vendor:siemensmodel:ccis1425scope: - version: -

Trust: 0.8

vendor:siemensmodel:ccmd3025-dn18scope: - version: -

Trust: 0.8

vendor:siemensmodel:ccmd3025-dn18scope:ltversion:1.394_s1

Trust: 0.8

vendor:siemensmodel:ccms2025scope: - version: -

Trust: 0.8

vendor:siemensmodel:ccmw1025scope: - version: -

Trust: 0.8

vendor:siemensmodel:ccmw3025scope: - version: -

Trust: 0.8

vendor:siemensmodel:ccmw3025scope:ltversion:1.41_sp18_s1

Trust: 0.8

vendor:siemensmodel:ccpw3025scope: - version: -

Trust: 0.8

vendor:siemensmodel:ccpw3025scope:ltversion:0.1.73_s1

Trust: 0.8

vendor:siemensmodel:ccpw5025scope: - version: -

Trust: 0.8

vendor:siemensmodel:ccpw5025scope:ltversion:0.1.73_s1

Trust: 0.8

vendor:siemensmodel:cfis1425scope: - version: -

Trust: 0.8

vendor:siemensmodel:cfms2025scope: - version: -

Trust: 0.8

vendor:siemensmodel:cfmw1025scope: - version: -

Trust: 0.8

vendor:siemensmodel:cfmw3025scope: - version: -

Trust: 0.8

vendor:siemensmodel:cfmw3025scope:ltversion:1.41_sp18_s1

Trust: 0.8

vendor:siemensmodel:cvms2025-irscope: - version: -

Trust: 0.8

vendor:siemensmodel:cvmw3025-irscope: - version: -

Trust: 0.8

vendor:siemensmodel:cvmw3025-irscope:ltversion:1.41_sp18_s1

Trust: 0.8

vendor:siemensmodel:ccmw3025 <1.41 sp18 s1scope: - version: -

Trust: 0.6

vendor:siemensmodel:cvmw3025-ir <1.41 sp18 s1scope: - version: -

Trust: 0.6

vendor:siemensmodel:cfmw3025 <1.41 sp18 s1scope: - version: -

Trust: 0.6

vendor:siemensmodel:ccpw3025 <0.1.73 s1scope: - version: -

Trust: 0.6

vendor:siemensmodel:ccpw5025 <0.1.73 s1scope: - version: -

Trust: 0.6

vendor:siemensmodel:ccmd3025-dn18 <1.394 s1scope: - version: -

Trust: 0.6

vendor:siemensmodel:cvmw3025-irscope:eqversion:0

Trust: 0.3

vendor:siemensmodel:cvms2025-irscope:eqversion:0

Trust: 0.3

vendor:siemensmodel:cfmw3025scope:eqversion:0

Trust: 0.3

vendor:siemensmodel:cfmw1025scope:eqversion:0

Trust: 0.3

vendor:siemensmodel:cfms2025scope:eqversion:0

Trust: 0.3

vendor:siemensmodel:cfis1425scope:eqversion:0

Trust: 0.3

vendor:siemensmodel:ccpw5025scope:eqversion:0

Trust: 0.3

vendor:siemensmodel:ccpw3025scope:eqversion:0

Trust: 0.3

vendor:siemensmodel:ccmw3025scope:eqversion:0

Trust: 0.3

vendor:siemensmodel:ccmw1025scope:eqversion:0

Trust: 0.3

vendor:siemensmodel:ccms2025scope:eqversion:0

Trust: 0.3

vendor:siemensmodel:ccmd3025-dn18scope:eqversion:0

Trust: 0.3

vendor:siemensmodel:ccis1425scope:eqversion:0

Trust: 0.3

vendor:siemensmodel:ccid1445-dn36scope:eqversion:0

Trust: 0.3

vendor:siemensmodel:ccid1445-dn28scope:eqversion:0

Trust: 0.3

vendor:siemensmodel:ccid1445-dn18scope:eqversion:0

Trust: 0.3

vendor:siemensmodel:cvmw3025-ir 1.41 sp18 s1scope:neversion: -

Trust: 0.3

vendor:siemensmodel:cvms2025-irscope:neversion:2635

Trust: 0.3

vendor:siemensmodel:cfmw3025 1.41 sp18 s1scope:neversion: -

Trust: 0.3

vendor:siemensmodel:cfmw1025scope:neversion:2635

Trust: 0.3

vendor:siemensmodel:cfms2025scope:neversion:2635

Trust: 0.3

vendor:siemensmodel:cfis1425scope:neversion:2635

Trust: 0.3

vendor:siemensmodel:ccpw5025 0.1.73 s1scope:neversion: -

Trust: 0.3

vendor:siemensmodel:ccpw3025 0.1.73 s1scope:neversion: -

Trust: 0.3

vendor:siemensmodel:ccmw3025 1.41 sp18 s1scope:neversion: -

Trust: 0.3

vendor:siemensmodel:ccmw1025scope:neversion:2635

Trust: 0.3

vendor:siemensmodel:ccms2025scope:neversion:2635

Trust: 0.3

vendor:siemensmodel:ccmd3025-dn18 1.394 s1scope:neversion: -

Trust: 0.3

vendor:siemensmodel:ccis1425scope:neversion:2635

Trust: 0.3

vendor:siemensmodel:ccid1445-dn36scope:neversion:2635

Trust: 0.3

vendor:siemensmodel:ccid1445-dn28scope:neversion:2635

Trust: 0.3

vendor:siemensmodel:ccid1445-dn18scope:neversion:2635

Trust: 0.3

sources: CNVD: CNVD-2016-11370 // BID: 94392 // JVNDB: JVNDB-2016-005924 // CNNVD: CNNVD-201611-433 // NVD: CVE-2016-9155

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-9155
value: CRITICAL

Trust: 1.0

NVD: CVE-2016-9155
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2016-11370
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201611-433
value: MEDIUM

Trust: 0.6

VULHUB: VHN-97975
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2016-9155
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2016-11370
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-97975
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-9155
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2016-11370 // VULHUB: VHN-97975 // JVNDB: JVNDB-2016-005924 // CNNVD: CNNVD-201611-433 // NVD: CVE-2016-9155

PROBLEMTYPE DATA

problemtype:CWE-284

Trust: 1.1

problemtype:CWE-Other

Trust: 0.8

sources: VULHUB: VHN-97975 // JVNDB: JVNDB-2016-005924 // NVD: CVE-2016-9155

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201611-433

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201611-433

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-005924

PATCH

title:SSA-284765url:https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-284765.pdf

Trust: 0.8

title:SIEMENS-brandedIP-based CCTVcameras patch for information disclosure vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/84081

Trust: 0.6

title:Multiple Vanderbilt Industries Siemens IP CCTV Cameras Repair measures for device information disclosure vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=65774

Trust: 0.6

sources: CNVD: CNVD-2016-11370 // JVNDB: JVNDB-2016-005924 // CNNVD: CNNVD-201611-433

EXTERNAL IDS

db:NVDid:CVE-2016-9155

Trust: 3.5

db:BIDid:94392

Trust: 2.6

db:SIEMENSid:SSA-284765

Trust: 2.3

db:ICS CERTid:ICSA-16-322-01

Trust: 1.4

db:JVNDBid:JVNDB-2016-005924

Trust: 0.8

db:CNNVDid:CNNVD-201611-433

Trust: 0.7

db:CNVDid:CNVD-2016-11370

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

db:VULHUBid:VHN-97975

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2016-11370 // VULHUB: VHN-97975 // BID: 94392 // JVNDB: JVNDB-2016-005924 // CNNVD: CNNVD-201611-433 // NVD: CVE-2016-9155

REFERENCES

url:https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-284765.pdf

Trust: 2.3

url:http://www.securityfocus.com/bid/94392

Trust: 1.7

url:https://ics-cert.us-cert.gov/advisories/icsa-16-322-01

Trust: 1.4

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-9155

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-9155

Trust: 0.8

url:http://www.siemens.com/

Trust: 0.3

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2016-11370 // VULHUB: VHN-97975 // BID: 94392 // JVNDB: JVNDB-2016-005924 // CNNVD: CNNVD-201611-433 // NVD: CVE-2016-9155

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 94392

SOURCES

db:OTHERid: -
db:CNVDid:CNVD-2016-11370
db:VULHUBid:VHN-97975
db:BIDid:94392
db:JVNDBid:JVNDB-2016-005924
db:CNNVDid:CNNVD-201611-433
db:NVDid:CVE-2016-9155

LAST UPDATE DATE

2025-04-13T22:32:49.343000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-11370date:2016-11-21T00:00:00
db:VULHUBid:VHN-97975date:2016-12-23T00:00:00
db:BIDid:94392date:2016-11-24T01:11:00
db:JVNDBid:JVNDB-2016-005924date:2016-11-24T00:00:00
db:CNNVDid:CNNVD-201611-433date:2016-11-23T00:00:00
db:NVDid:CVE-2016-9155date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-11370date:2016-11-17T00:00:00
db:VULHUBid:VHN-97975date:2016-11-22T00:00:00
db:BIDid:94392date:2016-11-17T00:00:00
db:JVNDBid:JVNDB-2016-005924date:2016-11-24T00:00:00
db:CNNVDid:CNNVD-201611-433date:2016-11-22T00:00:00
db:NVDid:CVE-2016-9155date:2016-11-22T11:59:00.163