First published: Mon Feb 13 2017(Updated: )
An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded passwords is present in the SICAM PAS installations. Attackers might gain privileged access to the database over Port 2638/TCP.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SICAM PAS/PQS | <8.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8567 is considered a high-severity vulnerability due to the presence of hard-coded passwords allowing privileged access.
To fix CVE-2016-8567, upgrade your Siemens SICAM PAS to version 8.00 or later to eliminate the hard-coded factory account passwords.
CVE-2016-8567 affects Siemens SICAM PAS installations prior to version 8.00.
If exploited, CVE-2016-8567 allows attackers to gain unauthorized privileged access to the database through an unsecured TCP port.
There is no official workaround for CVE-2016-8567; the recommended action is to upgrade to the latest version.