CVE-2016-5848: Infoleak
Published Jul 4, 2016
·Updated
Siemens SICAM PAS before 8.07 does not properly restrict password data in the database, which makes it easier for local users to calculate passwords by leveraging unspecified database privileges.
Affected Software
1 affected component
Siemens Sicam Pas\/pqs<=8.07
Event History
Jul 4, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5848?
CVE-2016-5848 has a medium severity rating due to potential password exploitation risks.
2
How do I fix CVE-2016-5848?
To fix CVE-2016-5848, upgrade to Siemens SICAM PAS version 8.08 or later, which addresses this vulnerability.
3
Who is affected by CVE-2016-5848?
CVE-2016-5848 affects users of Siemens SICAM PAS versions prior to 8.07.
4
What type of attack can exploit CVE-2016-5848?
CVE-2016-5848 can be exploited by local users with specific database privileges to recalibrate passwords.
5
Is there a workaround for CVE-2016-5848?
There are no specific workarounds for CVE-2016-5848; the recommended action is to update the affected software.