SB2016101308 - Information disclosure in Siemens SIMATIC STEP 7
Published: October 13, 2016 Updated: October 14, 2016
Security Bulletin ID
SB2016101308
CSH Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Information disclosure (CVE-ID: CVE-2016-7959)
CWE-ID: CWE-326 - Inadequate Encryption Strength
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear
The vulnerability allows a local user with read access to TIA project files to obtain potentially sensitive information on the target system.
The weakness is due to inadequate encryption strength that lets attacker perform brute-force attack and view important files.
Successful exploitation of the vulnerability results in disclosure of potentially sensitive data on the vulnerable system.
Remediation
Install update from vendor's website.