CVE-2016-7960
published 2016-10-13CVE-2016-7960: Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for local…
PriorityP47low2.5CVSS 3.0
AVLACHPRLUINSUCLINAN
EPSS
0.33%
25.3th percentile
Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for local users to obtain sensitive configuration information via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_step_7 | <= 13.010 | — |
CVSS provenance
nvdv3.02.5LOWCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fqrr-2f45-vg28: Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for
ghsa_unreviewed·2022-05-17
CVE-2016-7960 [LOW] CWE-200 GHSA-fqrr-2f45-vg28: Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for
Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for local users to obtain sensitive configuration information via unspecified vectors.
CISA ICS
Siemens SIMATIC STEP 7 (TIA Portal) Information Disclosure Vulnerabilities
cisa_ics·2016-10-13
Siemens SIMATIC STEP 7 (TIA Portal) Information Disclosure Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC STEP 7 (TIA Portal) Information Disclosure Vulnerabilities
Last RevisedOctober 13, 2016
Alert CodeICSA-16-287-03
## OVERVIEW
Siemens has released a new version of SIMATIC STEP 7 (TIA Portal) to mitigate information disclosure vulnerabilities. These vulnerabilities were reported directly to Siemens by Dmitry Sklyarov and Gleb Gritsai from Positive Technologies. Siemens has produced a new version to mitigate these vulnerabilities.
## AFFECTED PRODUCTS
Siemens reports that the vulnerabilities affect the following versions of SIMATIC STEP 7 (TIA Portal):
- SIMATIC
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/93551http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-869766.pdfhttps://ics-cert.us-cert.gov/advisories/ICSA-16-287-03http://www.securityfocus.com/bid/93551http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-869766.pdfhttps://ics-cert.us-cert.gov/advisories/ICSA-16-287-03
2016-10-13
Published