Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Siemens SIMATIC STEP 7 (TIA Portal) before 14 improperly stores pre-shared key data in TIA project files, which makes it easier for local users to obtain sensitive information by leveraging access to a file and conducting a brute-force attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Siemens SIMATIC STEP 7 安全漏洞
Vulnerability Description
Siemens SIMATIC STEP 7(TIA Portal)是德国西门子(Siemens)公司的一套用于SIMATIC控制器的编程软件。该软件提供PLC编程、设计选件包和先进的驱动器技术等。 Siemens SIMATIC STEP 7(TIA Portal) 13.010及之前的版本中存在安全漏洞,该漏洞源于程序没有在TIA项目文件中正确存储pre-shared密钥数据。本地攻击者可通过实施暴力破解攻击访问文件利用该漏洞获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A