CVE-2016-5744: Infoleak
Published Jul 22, 2016
·Updated
Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC station files via crafted packets.
Affected Software
5 affected components
Siemens SIMATIC WinCC=7.0
Siemens SIMATIC WinCC=7.0-sp1
Siemens SIMATIC WinCC=7.0-sp2
Siemens SIMATIC WinCC=7.0-sp3
Siemens SIMATIC WinCC=7.2
Event History
Jul 22, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5744?
CVE-2016-5744 is rated as high severity due to its potential to allow remote attackers to access sensitive files.
2
How do I fix CVE-2016-5744?
To fix CVE-2016-5744, it is recommended to update to a newer version of Siemens SIMATIC WinCC beyond 7.2.
3
What are the affected versions for CVE-2016-5744?
The affected versions of Siemens SIMATIC WinCC are 7.0 through SP3 and 7.2.
4
Can CVE-2016-5744 be exploited remotely?
Yes, CVE-2016-5744 can be exploited remotely by attackers sending crafted packets.
5
What type of data is at risk with CVE-2016-5744?
CVE-2016-5744 puts arbitrary WinCC station files at risk of being read by remote attackers.