WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Siemens CP1604 and CP1616 (Update A) (ICSA-19-043-06) – Products Used in the Water and Wastewater Sector
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Siemens CP1604 and CP1616 (Update A) (ICSA-19-043-06) – Products Used in the Water and Wastewater Sector

Author: Charles Egli

Created: Wednesday, July 10, 2019 - 20:10

Categories: Cybersecurity

July 9, 2019

The NCCIC has updated this advisory with additional information on mitigation measures. Read the advisory at CISA.

February 12, 2019

The NCCIC has published an advisory on cleartext transmission of sensitive information, cross-site scripting, and cross-site request forgery vulnerabilities in Siemens CP1604 and CP1616. All versions of these products prior to 2.8 are affected. Successful exploitation of these vulnerabilities could result in a denial-of-service condition and information exposure. An attacker could inject arbitrary JavaScript in a specially crafted URL request to execute on unsuspecting user’s systems, allowing an attacker to trigger actions via the web interface that a legitimate user is allowed to perform. Siemens recommends users upgrade to version 2.8. The NCCIC also advises of a series of measures for mitigating these vulnerabilities. Read the advisory at NCCIC/ICS-CERT.

Related Resources

(TLP:CLEAR) FIRESTARTER Backdoor and Updated Emergency Directive for CISCO Firepower and Secure Firewall Devices

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:GREEN) FBI FLASH – Newly Observed Ransomware Variant Black Shrantac Threat to U.S. Entities

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Likely PRC State-Sponsored Activity Observed in the Water Sector – DocuSign Phishing Tactics Identified

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar