CVE-2016-9155

high-risk
Published 2016-11-22

The following SIEMENS branded IP Camera Models CCMW3025, CVMW3025-IR, CFMW3025 prior to version 1.41_SP18_S1; CCPW3025, CCPW5025 prior to version 0.1.73_S1; CCMD3025-DN18 prior to version v1.394_S1; CCID1445-DN18, CCID1445-DN28, CCID1145-DN36, CFIS1425, CCIS1425, CFMS2025, CCMS2025, CVMS2025-IR, CFMW1025, CCMW1025 prior to version v2635_SP1 could allow an attacker with network access to the web server to obtain administrative credentials under certain circumstances.

Do I need to act?

-
0.92% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10 Critical
NETWORK / LOW complexity

Affected Products (15)

Ccid1445-Dn18 Firmware
Ccid1445-Dn28 Firmware
Ccis1425 Firmware
Ccms2025 Firmware
Cfis1425 Firmware
Cfms2025 Firmware
Cfmw1025 Firmware
Cvms2025-Ir Firmware
Ccid1445-Dn36 Firmware
Ccmd3025-Dn18 Firmware
Ccmw1025 Firmware
Ccmw3025 Firmware
Ccpw3025 Firmware
Cfmw3025 Firmware
Cvmw3025-Ir Firmware

Affected Vendors

53
/ 100
high-risk
Severity 32/34 · Critical
Exploitability 3/34 · Minimal
Exposure 18/34 · Moderate