Siemens SICAM PAS before 8.07 does not properly restrict password data in the database, which makes it easier for local users to calculate passwords by leveraging unspecified database privileges.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-16-182-02 | third party advisory us government resource |
http://www.securityfocus.com/bid/91525 | vdb entry third party advisory |
http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-444217.pdf | vendor advisory |