NVD
- Id
- 21689
- Name
- CVE-2016-7165
- Description
- Unquoted Windows search path vulnerability in Siemens SIMATIC WinCC before 7.0 SP2 Upd 12, 7.0 SP3 before Upd 8, and 7.2 through 7.4; SIMATIC WinCC (TIA Portal) Basic, Comfort, Advanced before 14; SIMATIC WinCC Runtime Professional; SIMATIC WinCC (TIA Portal) Professional; SIMATIC STEP 7 5.x; SIMATIC STEP 7 (TIA Portal) before 14; SIMATIC NET PC-Software before 14; TeleControl Server Basic before 3.0 SP2; SINEMA Server before 13 SP2; SIMATIC PCS 7 through 8.2; SINEMA Remote Connect Client; SIMATIC WinAC RTX 2010 SP2; SIMATIC WinAC RTX F 2010 SP2; SIMATIC IT Production Suite; SOFTNET Security Client 5.0; SIMIT 9.0; Security Configuration Tool (SCT); and Primary Setup Tool (PST), when the installation does not use the %PROGRAMFILES% directory, might allow local users to gain privileges via a Trojan horse executable file.
- Reject
- CVSS Version
- 2
- CVSS Score
- 6.9
- Severity
- Medium
- CVSS Base Score
- 6.9
- CVSS Impact Subscore
- 10
- CVSS Exploit Subscore
- 3.4
- CVSS Vector
- (AV:L/AC:M/Au:N/C:C/I:C/A:C)
- Pub Date
- 2017-01-19
- Published
- 2016-11-15
- Modified Date
- 2017-01-03
- Seq
- 2016-7165