CVE-2016-7987: Siemens ETA2 Firmware

High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.

An issue was discovered in Siemens ETA4 firmware (all versions prior to Revision 08) of the SM-2558 extension module for: SICAM AK, SICAM TM 1703, SICAM BC 1703, and SICAM AK 3. Specially crafted packets sent to Port 2404/TCP could cause the affected device to go into defect mode. A cold start might be required to recover the system, a Denial-of-Service Vulnerability.

Affected products

  • Siemens ETA2 Firmware: up to and including 11.0
  • Siemens ETA4 Firmware: up to and including 07

Published 2017-02-13. Last modified 2026-06-17.