CVE-2017-12737 describes an information disclosure vulnerability affecting Siemens SICAM RTUs SM-2556 COM Modules with specific firmware variants. Unauthenticated remote attackers can leverage the integrated web server (port 80/tcp) to obtain sensitive device information. Rated as Medium severity (CVSS 5.3), this vulnerability has a low impact on confidentiality and requires no user interaction or privileges. There is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB, despite a single media report incorrectly mentioning remote code execution. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
dnpi00CPE matchmatch criteria | cpe:2.3:o:siemens:sm-2556_firmware:dnpi00:*:*:*:*:*:*:* | ||
enos00CPE matchmatch criteria | cpe:2.3:o:siemens:sm-2556_firmware:enos00:*:*:*:*:*:*:* | ||
erac00CPE matchmatch criteria | cpe:2.3:o:siemens:sm-2556_firmware:erac00:*:*:*:*:*:*:* | ||
eta2CPE matchmatch criteria | cpe:2.3:o:siemens:sm-2556_firmware:eta2:*:*:*:*:*:*:* | ||
etls00CPE matchmatch criteria | cpe:2.3:o:siemens:sm-2556_firmware:etls00:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.