CVE-2016-5744
published 2016-07-22CVE-2016-5744: Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC station files via crafted packets.
PriorityP347high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
4.40%
90.3th percentile
Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC station files via crafted packets.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g5pr-xc4w-x864: Siemens SIMATIC WinCC 7
ghsa_unreviewed·2022-05-17
CVE-2016-5744 [HIGH] CWE-200 GHSA-g5pr-xc4w-x864: Siemens SIMATIC WinCC 7
Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC station files via crafted packets.
CISA ICS
Siemens SIMATIC WinCC, PCS 7, and WinCC Runtime Professional Vulnerabilities (Update C)
cisa_ics·2016-10-04
Siemens SIMATIC WinCC, PCS 7, and WinCC Runtime Professional Vulnerabilities (Update C)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC WinCC, PCS 7, and WinCC Runtime Professional Vulnerabilities (Update C)
Last RevisedNovember 08, 2016
Alert CodeICSA-16-208-01C
## OVERVIEW
This updated advisory is a follow-up to the advisory update titled ICSA-16-208-01B Siemens SIMATIC WinCC, PCS 7, and WinCC Runtime Professional Vulnerabilities that was published October 4, 2016, on the NCCIC/ICS-CERT web site.
Siemens has identified two vulnerabilities in SIMATIC WinCC, PCS 7, and WinCC Runtime Professional. Sergey Temnikov and Vladimir Dashchenko from Kaspersky Lab reported these issues directly to Siemens
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/92116http://www.securitytracker.com/id/1036441http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-378531.pdfhttps://ics-cert.us-cert.gov/advisories/ICSA-16-208-01http://www.securityfocus.com/bid/92116http://www.securitytracker.com/id/1036441http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-378531.pdfhttps://ics-cert.us-cert.gov/advisories/ICSA-16-208-01
2016-07-22
Published