CVE-2016-5743

critical
Published 2016-07-22 · Modified 2026-05-06
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
10.0
VIR risk
9.8

Description

Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Update 9 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.1 Update 3 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.2 Update 1 as distributed in SIMATIC PCS 7 8.2, and SIMATIC WinCC Runtime Professional before 13 SP1 Update 9 allow remote attackers to execute arbitrary code via crafted packets.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-378531.pdf

Application impact

VendorProductVersionsFixed
siemens siemenssimatic_batch{"endIncluding":"7.1"}
siemens siemenssimatic_wincc{"endIncluding":"7.3"}
siemens siemenssimatic_pcs_7{"endIncluding":"8.1"}
siemens siemenssimatic_openpcs_7{"endIncluding":"8.1"}
siemens siemenssimatic_wincc_runtime_professional{"endIncluding":"13"}

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.