PatchSiren cyber security CVE debrief
CVE-2016-5796 Fatek CVE debrief
CVE-2016-5796 is a memory-corruption flaw in Fatek Automation PM Designer V3 2.1.2.2 and Automation FV Designer 1.2.8.0. According to the public record, sending additional valid packets can trigger a crash or potentially arbitrary code execution. NVD scores the issue HIGH (8.8) and maps it to CWE-119.
- Vendor
- Fatek
- Product
- Unknown
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2016-07-17
- Original CVE updated
- 2025-06-05
- Advisory published
- 2016-07-17
- Advisory updated
- 2025-06-05
Who should care
Organizations that use Fatek engineering/design software, especially OT/ICS teams, automation engineers, and IT admins supporting those workstations.
Technical summary
The official record describes an improper restriction of operations within the bounds of a memory buffer. NVD lists affected CPEs for Automation FV Designer 1.2.8.0 and Automation PM Designer V3 2.1.2.2, with a CVSS v3.0 vector of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The public description does not spell out every precondition, but the rating indicates network reachability and some user interaction are involved.
Defensive priority
High. The issue can lead to denial of service and possible code execution in engineering software used in industrial environments.
Recommended defensive actions
- Identify whether Automation PM Designer V3 2.1.2.2 or Automation FV Designer 1.2.8.0 is installed anywhere in the environment.
- Follow the vendor or ICS-CERT guidance referenced in the public advisory for remediation or mitigation steps.
- Restrict network and workstation access to engineering tools so only trusted users and systems can reach them.
- Monitor affected systems for unexplained crashes, abnormal packet handling, or unexpected process behavior.
- Apply least privilege and isolate OT engineering workstations from untrusted networks where feasible.
- Keep backups of project files and workstation images so affected systems can be rebuilt quickly if needed.
Evidence notes
NVD’s public record for CVE-2016-5796 identifies the issue as a buffer-bound restriction problem (CWE-119) and lists the CVSS v3.0 vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The record references ICS-CERT advisory ICSA-16-287-06 and SecurityFocus BID 93105, and the NVD CPE mappings name Fatek Automation FV Designer 1.2.8.0 and Automation PM Designer V3 2.1.2.2.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-5796 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-5796
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-5796 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-5796
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://ics-cert.us-cert.gov/advisories/ICSA-16-287-06
[email protected] - Mitigation, Third Party Advisory, US Government Resource
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.