CVE-2016-5848

Siemens SICAM PAS before 8.07 does not properly restrict password data in the database, which makes it easier for local users to calculate passwords by leveraging unspecified database privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:siemens:sicam_pas\/pqs:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:55

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/91525 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/91525 - Third Party Advisory, VDB Entry
References () http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-444217.pdf - Vendor Advisory () http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-444217.pdf - Vendor Advisory
References () https://ics-cert.us-cert.gov/advisories/ICSA-16-182-02 - Third Party Advisory, US Government Resource () https://ics-cert.us-cert.gov/advisories/ICSA-16-182-02 - Third Party Advisory, US Government Resource

17 Oct 2023, 19:05

Type Values Removed Values Added
CPE cpe:2.3:a:siemens:sicam_pas\/pqs:*:*:*:*:*:*:*:*
References (MISC) https://ics-cert.us-cert.gov/advisories/ICSA-16-182-02 - (MISC) https://ics-cert.us-cert.gov/advisories/ICSA-16-182-02 - Third Party Advisory, US Government Resource
References (BID) http://www.securityfocus.com/bid/91525 - (BID) http://www.securityfocus.com/bid/91525 - Third Party Advisory, VDB Entry
First Time Siemens
Siemens sicam Pas\/pqs

13 Oct 2023, 16:45

Type Values Removed Values Added
CPE cpe:2.3:a:siemens:sicam_pas:*:*:*:*:*:*:*:*

Information

Published : 2016-07-04 16:59

Updated : 2024-11-21 02:55


NVD link : CVE-2016-5848

Mitre link : CVE-2016-5848

CVE.ORG link : CVE-2016-5848


JSON object : View

Products Affected

siemens

  • sicam_pas\/pqs
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-255

Credentials Management Errors