CVE-2016-9160: High severity siemens simatic pcs 7 telecontrol firmware vulnerability
A vulnerability in SIEMENS SIMATIC WinCC (All versions < SIMATIC WinCC V7.2) and SIEMENS SIMATIC PCS 7 (All versions < SIMATIC PCS 7 V8.0 SP1) could allow a remote attacker to crash an ActiveX component or leak parts of the application memory if a user is tricked into clicking on a malicious link under certain conditions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9160?
CVE-2016-9160 is rated as high severity due to the potential for remote code execution and application memory leaks.
How do I fix CVE-2016-9160?
To fix CVE-2016-9160, upgrade to SIEMENS SIMATIC WinCC V7.2 or SIEMENS SIMATIC PCS 7 V8.0 SP1 or later.
What software versions are affected by CVE-2016-9160?
CVE-2016-9160 affects all versions of SIEMENS SIMATIC WinCC prior to V7.2 and all versions of SIEMENS SIMATIC PCS 7 prior to V8.0 SP1.
Can CVE-2016-9160 be exploited remotely?
Yes, CVE-2016-9160 can be exploited remotely if a user is tricked into clicking on a malicious link.
What type of impact can CVE-2016-9160 have on my system?
The impact of CVE-2016-9160 can include application crashes and potentially leaking sensitive parts of application memory.