CVE-2016-7960Sensitive Information Exposure in Siemens Simatic Step 7

Severity
2.5LOWNVD
EPSS
0.1%
top 74.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 13
Latest updateMay 17

Description

Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for local users to obtain sensitive configuration information via unspecified vectors.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.0 | Impact: 1.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fqrr-2f45-vg28: Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for2022-05-17
CVEList
CVE-2016-7960: Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for2016-10-13
CVE-2016-7960 — Sensitive Information Exposure | cvebase