CVE-2016-7959: Medium severity simatic step 7 vulnerability
Published Oct 13, 2016
·Updated
Siemens SIMATIC STEP 7 (TIA Portal) before 14 improperly stores pre-shared key data in TIA project files, which makes it easier for local users to obtain sensitive information by leveraging access to a file and conducting a brute-force attack.
Affected Software
1 affected component
Siemens SIMATIC STEP 7<=13.010
Event History
Oct 13, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7959?
CVE-2016-7959 is classified as a medium severity vulnerability due to its potential for local exploitation.
2
How do I fix CVE-2016-7959?
To mitigate CVE-2016-7959, upgrade to Siemens SIMATIC STEP 7 version 14 or later.
3
What type of data is improperly stored in CVE-2016-7959?
CVE-2016-7959 improperly stores pre-shared key data in TIA project files.
4
Who is affected by CVE-2016-7959?
CVE-2016-7959 affects users of Siemens SIMATIC STEP 7 versions up to and including 13.010.
5
How can local users exploit CVE-2016-7959?
Local users can exploit CVE-2016-7959 to obtain sensitive information through brute-force attacks on accessible project files.