PT-2015-3310 · Siemens · Simatic Step 7
Dmitry Sklyarov
+1
·
Published
2015-01-15
·
Updated
2016-12-22
·
CVE-2016-7959
CVSS v3.1
4.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Siemens SIMATIC STEP 7 (TIA Portal) versions prior to 14
Description
The issue is related to the incorrect storage of pre-shared keys in TIA project files. This could allow a local attacker to gain access to sensitive information, potentially by conducting a brute-force attack after obtaining access to a file.
Recommendations
For versions prior to 14, update to version 14 or later to resolve the issue. As a temporary workaround, consider restricting access to TIA project files to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic Step 7