CVE-2012-3015: Medium severity Siemens SIMATIC PCS7 vulnerability
Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7 7.1 SP3 and earlier and other products, allows local users to gain privileges via a Trojan horse DLL in a STEP7 project folder.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3015?
CVE-2012-3015 is classified as a medium severity vulnerability that allows local users to gain elevated privileges.
How do I fix CVE-2012-3015?
To resolve CVE-2012-3015, users should update to Siemens SIMATIC STEP 7 version 5.5 SP1 or later.
What types of systems are affected by CVE-2012-3015?
CVE-2012-3015 affects Siemens SIMATIC STEP 7 versions prior to 5.5 SP1 and SIMATIC PCS 7 up to version 7.1 SP3.
What kind of attack can exploit CVE-2012-3015?
CVE-2012-3015 can be exploited by placing a Trojan horse DLL in the STEP7 project folder, allowing privilege escalation.
Is there a workaround for CVE-2012-3015 if I cannot update?
A potential workaround for CVE-2012-3015 is to restrict access to the STEP7 project folders to trusted users only.