Siemens Simatic Step 7 vulnerabilities
24 known vulnerabilities affecting siemens/simatic_step_7.
Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
HIGH8MEDIUM13LOW3
Vulnerabilities
Page 2 of 2
CVE-2016-7959P4MEDIUMCVSS 4.7≤ 13.0102016-10-13
CVE-2016-7959 [MEDIUM] CWE-254 CVE-2016-7959: Siemens SIMATIC STEP 7 (TIA Portal) before 14 improperly stores pre-shared key data in TIA project f
Siemens SIMATIC STEP 7 (TIA Portal) before 14 improperly stores pre-shared key data in TIA project files, which makes it easier for local users to obtain sensitive information by leveraging access to a file and conducting a brute-force attack.
nvd
CVE-2015-1602P4LOWCVSS 2.1≤ 13.0v12.0+1 more2015-04-06
CVE-2015-1602 [LOW] CWE-200 CVE-2015-1602: Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data wit
Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data within project files, which makes it easier for local users to determine cleartext (1) protection-level passwords or (2) web-server passwords by leveraging the ability to read these files.
nvd
CVE-2016-7960P4LOWCVSS 2.5≤ 13.0102016-10-13
CVE-2016-7960 [LOW] CWE-200 CVE-2016-7960: Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files
Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for local users to obtain sensitive configuration information via unspecified vectors.
nvd
CVE-2015-1355P4LOWCVSS 2.1≤ 13.02015-02-18
CVE-2015-1355 [LOW] CWE-310 CVE-2015-1355: Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes i
Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes it easier for local users to determine cleartext passwords by reading a project file and conducting a brute-force attack.
nvd
← Previous2 / 2