Description
Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D (All firmware versions < V6.00.046) and Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 for Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U (All firmware versions < V6.00.046) use a pseudo random number generator with insufficient entropy to generate certificates for HTTPS, potentially allowing remote attackers to reconstruct the corresponding private key.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-9971 | Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D (All firmware versions < V6.00.046) and Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 for Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U (All firmware versions < V6.00.046) use a pseudo random number generator with insufficient entropy to generate certificates for HTTPS, potentially allowing remote attackers to reconstruct the corresponding private key. |
References
History
No history.
Subscriptions
Siemens
Subscribe
Desigo Web Module Pxa30-w0
Subscribe
Desigo Web Module Pxa30-w0 Firmware
Subscribe
Desigo Web Module Pxa30-w1
Subscribe
Desigo Web Module Pxa30-w1 Firmware
Subscribe
Desigo Web Module Pxa30-w2
Subscribe
Desigo Web Module Pxa30-w2 Firmware
Subscribe
Desigo Web Module Pxa40-w0
Subscribe
Desigo Web Module Pxa40-w0 Firmware
Subscribe
Desigo Web Module Pxa40-w1
Subscribe
Desigo Web Module Pxa40-w1 Firmware
Subscribe
Desigo Web Module Pxa40-w2
Subscribe
Desigo Web Module Pxa40-w2 Firmware
Subscribe
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-08-06T02:42:11.004Z
Reserved: 2016-11-03T00:00:00.000Z
Link: CVE-2016-9154
No data.
Status : Modified
Published: 2016-12-23T05:59:00.593
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-9154
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD