Lucene search

K
nvd[email protected]NVD:CVE-2015-1594
HistoryMar 07, 2015 - 2:59 a.m.

CVE-2015-1594

2015-03-0702:59:03
web.nvd.nist.gov
4

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

5.1%

Untrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0 SP4 Upd9 and 8.1 before Upd1; SIMATIC STEP 7 before 5.5 SP1 HF2, 5.5 SP2 before HF7, 5.5 SP3, and 5.5 SP4 before HF4; SIMOTION Scout before 4.4; and STARTER before 4.4 HF3 allows local users to gain privileges via a Trojan horse application file.

Affected configurations

Nvd
Node
siemensstarterRange4.4
Node
siemenssimatic_prosaveMatch13.0
Node
siemenssimotion_scoutRange4.3sp1
Node
siemenssimatic_cfcRange8.0sp4
OR
siemenssimatic_cfcMatch8.1
Node
siemenssimatic_step_7Range5.5sp1
OR
siemenssimatic_step_7Match5.5sp2
OR
siemenssimatic_step_7Match5.5sp3
OR
siemenssimatic_step_7Match5.5sp4
VendorProductVersionCPE
siemensstarter*cpe:2.3:a:siemens:starter:*:*:*:*:*:*:*:*
siemenssimatic_prosave13.0cpe:2.3:a:siemens:simatic_prosave:13.0:*:*:*:*:*:*:*
siemenssimotion_scout*cpe:2.3:a:siemens:simotion_scout:*:sp1:*:*:*:*:*:*
siemenssimatic_cfc*cpe:2.3:a:siemens:simatic_cfc:*:sp4:*:*:*:*:*:*
siemenssimatic_cfc8.1cpe:2.3:a:siemens:simatic_cfc:8.1:*:*:*:*:*:*:*
siemenssimatic_step_7*cpe:2.3:a:siemens:simatic_step_7:*:sp1:*:*:*:*:*:*
siemenssimatic_step_75.5cpe:2.3:a:siemens:simatic_step_7:5.5:sp2:*:*:*:*:*:*
siemenssimatic_step_75.5cpe:2.3:a:siemens:simatic_step_7:5.5:sp3:*:*:*:*:*:*
siemenssimatic_step_75.5cpe:2.3:a:siemens:simatic_step_7:5.5:sp4:*:*:*:*:*:*

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

5.1%

Related for NVD:CVE-2015-1594