#VU995 Information disclosure in SIMATIC STEP 7 - CVE-2016-7960
Published: October 14, 2016
Vulnerability identifier: #VU995
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2016-7960
CWE-ID: CWE-310
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
SIMATIC STEP 7
SIMATIC STEP 7
Software vendor:
Siemens
Siemens
Description
The vulnerability allows a local user to obtain potentially sensitive configuration settings on the target system.
The weakness is due to cryptographic issues that lets attacker bypass protection of the transport format of TIA Portal project files and view important files.
Successful exploitation of the vulnerability results in disclosure of potentially sensitive data on the vulnerable system.
The weakness is due to cryptographic issues that lets attacker bypass protection of the transport format of TIA Portal project files and view important files.
Successful exploitation of the vulnerability results in disclosure of potentially sensitive data on the vulnerable system.
Remediation
Update to version 14.