SB2016101308 - Information disclosure in Siemens SIMATIC STEP 7
Published: October 13, 2016 Updated: October 14, 2016
Security Bulletin ID
SB2016101308
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2016-7959)
The vulnerability allows a local user with read access to TIA project files to obtain potentially sensitive information on the target system.The weakness is due to inadequate encryption strength that lets attacker perform brute-force attack and view important files.
Successful exploitation of the vulnerability results in disclosure of potentially sensitive data on the vulnerable system.
Remediation
Install update from vendor's website.