PT-2015-3310 · Siemens · Simatic Step 7

Dmitry Sklyarov

+1

·

Published

2015-01-15

·

Updated

2016-12-22

·

CVE-2016-7959

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Siemens SIMATIC STEP 7 (TIA Portal) versions prior to 14
Description The issue is related to the incorrect storage of pre-shared keys in TIA project files. This could allow a local attacker to gain access to sensitive information, potentially by conducting a brute-force attack after obtaining access to a file.
Recommendations For versions prior to 14, update to version 14 or later to resolve the issue. As a temporary workaround, consider restricting access to TIA project files to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02201
CVE-2016-7959

Affected Products

Simatic Step 7