CVE-2016-7114 describes an authentication bypass vulnerability affecting various Siemens EN100 Ethernet module firmware versions and devices like SIPROTEC Merging Units. An attacker with network access to the device's web interface (port 80/tcp) could perform administrative operations if a legitimate user is already logged in. This vulnerability carries a CVSSv3 score of 8.8 (High), indicating a network-based attack with low complexity and high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, it has a low EPSS score and no public exploit code, but has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.28CPE matchmatch criteria | cpe:2.3:a:siemens:en100_ethernet_module_firmware:4.28:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.