Lucene search

K
cveIcscertCVE-2012-3015
HistoryJul 26, 2012 - 10:41 a.m.

CVE-2012-3015

2012-07-2610:41:47
icscert
web.nvd.nist.gov
47
4
cve-2012-3015
siemens simatic step7
untrusted search path
vulnerability
privilege escalation
nvd

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

32.6%

Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7 7.1 SP3 and earlier and other products, allows local users to gain privileges via a Trojan horse DLL in a STEP7 project folder.

Affected configurations

Nvd
Node
siemenssimatic_pcs7Range7.1sp3
OR
siemenssimatic_step_7Range5.5
VendorProductVersionCPE
siemenssimatic_pcs7*cpe:2.3:a:siemens:simatic_pcs7:*:sp3:*:*:*:*:*:*
siemenssimatic_step_7*cpe:2.3:a:siemens:simatic_step_7:*:*:*:*:*:*:*:*

Social References

More

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

32.6%

Related for CVE-2012-3015