PT-2016-6669 · Siemens · Simatic Wincc
Published
2016-07-22
·
Updated
2016-11-28
·
CVE-2016-5744
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Siemens SIMATIC WinCC versions 7.0 through 7.2
Description
The issue allows remote attackers to read arbitrary WinCC station files by sending crafted packets.
Recommendations
For versions 7.0 through 7.2, update to a version that includes the fix for this issue to prevent remote attackers from reading arbitrary files.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic Wincc