#VU995 Information disclosure in SIMATIC STEP 7 - CVE-2016-7960 

 

#VU995 Information disclosure in SIMATIC STEP 7 - CVE-2016-7960

Published: October 14, 2016


Vulnerability identifier: #VU995
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2016-7960
CWE-ID: CWE-310
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
SIMATIC STEP 7
Software vendor:
Siemens

Description

The vulnerability allows a local user to obtain potentially sensitive configuration settings on the target system.
The weakness is due to cryptographic issues that lets attacker bypass protection of the transport format of TIA Portal project files and view important files.
Successful exploitation of the vulnerability results in disclosure of potentially sensitive data on the vulnerable system.

Remediation

Update to version 14.

External links