Information disclosure in SIMATIC STEP 7 - CVE-2016-7960
Published: October 14, 2016
Vulnerability identifier: #VU995
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2016-7960
CWE-ID: CWE-310
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Siemens
Affected software:
SIMATIC STEP 7
SIMATIC STEP 7
Detailed vulnerability description
The vulnerability allows a local user to obtain potentially sensitive configuration settings on the target system.
The weakness is due to cryptographic issues that lets attacker bypass protection of the transport format of TIA Portal project files and view important files.
Successful exploitation of the vulnerability results in disclosure of potentially sensitive data on the vulnerable system.
The weakness is due to cryptographic issues that lets attacker bypass protection of the transport format of TIA Portal project files and view important files.
Successful exploitation of the vulnerability results in disclosure of potentially sensitive data on the vulnerable system.
How to mitigate CVE-2016-7960
Update to version 14.