PT-2016-3178 · Siemens · Siemens Sicam Pas

Dmitry Sklyarov

+1

·

Published

2016-01-15

·

Updated

2023-10-17

·

CVE-2016-5848

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Siemens SICAM PAS versions prior to 8.07
Description The issue is related to insufficient password protection in the database of the Siemens SICAM PAS system, which can be exploited by a local attacker to calculate passwords using certain database privileges.
Recommendations For Siemens SICAM PAS versions prior to 8.07, update to version 8.07 or later to resolve the issue. As a temporary workaround, consider restricting access to the database and limiting privileges to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2017-02203
CVE-2016-5848

Affected Products

Siemens Sicam Pas