Vulnerability Details CVE-2016-7959
Siemens SIMATIC STEP 7 (TIA Portal) before 14 improperly stores pre-shared key data in TIA project files, which makes it easier for local users to obtain sensitive information by leveraging access to a file and conducting a brute-force attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 20.2%
CVSS Severity
CVSS v3 Score 4.7
CVSS v2 Score 1.9
Products affected by CVE-2016-7959
-
cpe:2.3:a:siemens:simatic_step_7:12.0
-
cpe:2.3:a:siemens:simatic_step_7:13
-
cpe:2.3:a:siemens:simatic_step_7:13.0
-
cpe:2.3:a:siemens:simatic_step_7:13.001
-
cpe:2.3:a:siemens:simatic_step_7:13.002
-
cpe:2.3:a:siemens:simatic_step_7:13.003
-
cpe:2.3:a:siemens:simatic_step_7:13.004
-
cpe:2.3:a:siemens:simatic_step_7:13.005
-
cpe:2.3:a:siemens:simatic_step_7:13.006
-
cpe:2.3:a:siemens:simatic_step_7:13.007
-
cpe:2.3:a:siemens:simatic_step_7:13.008
-
cpe:2.3:a:siemens:simatic_step_7:13.009
-
cpe:2.3:a:siemens:simatic_step_7:13.010
-
cpe:2.3:a:siemens:simatic_step_7:5.5
-
cpe:2.3:a:siemens:simatic_step_7:5.6