CVE-2012-3015

4 documents4 sources
Severity
6.9MEDIUM
EPSS
0.1%
top 81.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Latest updateMay 17

Description

Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7 7.1 SP3 and earlier and other products, allows local users to gain privileges via a Trojan horse DLL in a STEP7 project folder.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-jvr3-fqr5-pf4c: Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 52022-05-17
CVEList
CVE-2012-3015: Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 52012-07-26
VulnCheck
Siemens simatic_pcs7 Untrusted Search Path2012