CVE-2016-7960 — Sensitive Information Exposure in Siemens Simatic Step 7
Severity
2.5LOWNVD
EPSS
0.1%
top 74.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 13
Latest updateMay 17
Description
Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for local users to obtain sensitive configuration information via unspecified vectors.
CVSS vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.0 | Impact: 1.4
Affected Packages1 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-fqrr-2f45-vg28: Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for↗2022-05-17
CVEList▶
CVE-2016-7960: Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for↗2016-10-13