ID

VAR-201503-0016


CVE

CVE-2015-1594


TITLE

plural Siemens Vulnerability gained in products

Trust: 0.8

sources: JVNDB: JVNDB-2015-001703

DESCRIPTION

Untrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0 SP4 Upd9 and 8.1 before Upd1; SIMATIC STEP 7 before 5.5 SP1 HF2, 5.5 SP2 before HF7, 5.5 SP3, and 5.5 SP4 before HF4; SIMOTION Scout before 4.4; and STARTER before 4.4 HF3 allows local users to gain privileges via a Trojan horse application file. Supplementary information : CWE Vulnerability type by CWE-426: Untrusted Search Path ( Unreliable search path ) Has been identified. http://cwe.mitre.org/data/definitions/426.htmlA local user may be able to obtain permissions through the Trojan application file. Siemens SIMATIC ProSave, etc. are all products of Germany's Siemens (Siemens). Siemens SIMATIC ProSave is a product used in SIMATIC HMI panel for backup recovery and firmware update; SIMATIC CFC is a graphic editor, which is an optional core component of PCS 7 engineering system and STEP 7; SIMATIC STEP 7 is a The set provides PLC programming, design option package and other functions and is used for SIMATIC controller software

Trust: 2.61

sources: NVD: CVE-2015-1594 // JVNDB: JVNDB-2015-001703 // CNVD: CNVD-2015-01603 // IVD: 9e6aca98-2351-11e6-abef-000c29c66e3d // IVD: 4b925098-f6b1-42ef-a1d0-6f7cdce19847 // VULHUB: VHN-79555

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 1.0

sources: IVD: 9e6aca98-2351-11e6-abef-000c29c66e3d // IVD: 4b925098-f6b1-42ef-a1d0-6f7cdce19847 // CNVD: CNVD-2015-01603

AFFECTED PRODUCTS

vendor:siemensmodel:simatic cfcscope:eqversion:8.1

Trust: 2.2

vendor:siemensmodel:simatic prosavescope:eqversion:13.0

Trust: 1.6

vendor:siemensmodel:simatic step 7scope:eqversion:5.5

Trust: 1.6

vendor:simatic step 7model: - scope:eqversion:5.5

Trust: 1.2

vendor:siemensmodel:starterscope:lteversion:4.4

Trust: 1.0

vendor:siemensmodel:simotion scoutscope:lteversion:4.3

Trust: 1.0

vendor:siemensmodel:simatic step 7scope:lteversion:5.5

Trust: 1.0

vendor:siemensmodel:simatic cfcscope:lteversion:8.0

Trust: 1.0

vendor:siemensmodel:simatic step 7scope:eqversion:5.5 sp1 hf2

Trust: 0.8

vendor:siemensmodel:simatic cfcscope:ltversion:8.1

Trust: 0.8

vendor:siemensmodel:simatic pcs 7scope:eqversion:v8.1 (simatic step 7 sp4 hf4 cfc v8.1 upd1

Trust: 0.8

vendor:siemensmodel:simatic pcs 7scope:ltversion:)

Trust: 0.8

vendor:siemensmodel:simatic step 7scope:eqversion:5.5 sp3

Trust: 0.8

vendor:siemensmodel:simatic step 7scope:ltversion:5.5 sp4

Trust: 0.8

vendor:siemensmodel:simatic cfcscope:eqversion:v8.0 sp4 upd 9

Trust: 0.8

vendor:siemensmodel:simatic step 7scope:ltversion:5.5 sp2

Trust: 0.8

vendor:siemensmodel:simatic step 7scope:ltversion:5.5 sp1

Trust: 0.8

vendor:siemensmodel:simatic step 7scope:eqversion:5.5 sp2 hf7

Trust: 0.8

vendor:siemensmodel:simatic pcs 7scope:lteversion:v8.0 sp2 and earlier

Trust: 0.8

vendor:siemensmodel:simatic cfcscope:eqversion:8.1 upd1

Trust: 0.8

vendor:siemensmodel:simatic cfcscope:ltversion:8.0 sp4

Trust: 0.8

vendor:siemensmodel:simatic step 7scope:eqversion:5.5 sp4 hf4

Trust: 0.8

vendor:siemensmodel:simatic prosave sp1scope:ltversion:13

Trust: 0.6

vendor:siemensmodel:simatic cfc sp4 upd9scope:ltversion:8.0

Trust: 0.6

vendor:siemensmodel:starterscope:eqversion:4.4

Trust: 0.6

vendor:siemensmodel:simotion scoutscope:eqversion:4.3

Trust: 0.6

vendor:siemensmodel:simatic cfcscope:eqversion:8.0

Trust: 0.6

vendor:startermodel: - scope:eqversion:*

Trust: 0.4

vendor:simatic prosavemodel: - scope:eqversion:13.0

Trust: 0.4

vendor:simotion scoutmodel: - scope:eqversion:*

Trust: 0.4

vendor:simatic cfcmodel: - scope:eqversion:*

Trust: 0.4

vendor:simatic cfcmodel: - scope:eqversion:8.1

Trust: 0.4

vendor:simatic step 7model: - scope:eqversion:*

Trust: 0.4

sources: IVD: 9e6aca98-2351-11e6-abef-000c29c66e3d // IVD: 4b925098-f6b1-42ef-a1d0-6f7cdce19847 // CNVD: CNVD-2015-01603 // JVNDB: JVNDB-2015-001703 // CNNVD: CNNVD-201503-128 // NVD: CVE-2015-1594

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-1594
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-1594
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-01603
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201503-128
value: MEDIUM

Trust: 0.6

IVD: 9e6aca98-2351-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

IVD: 4b925098-f6b1-42ef-a1d0-6f7cdce19847
value: MEDIUM

Trust: 0.2

VULHUB: VHN-79555
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-1594
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-01603
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 9e6aca98-2351-11e6-abef-000c29c66e3d
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

IVD: 4b925098-f6b1-42ef-a1d0-6f7cdce19847
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-79555
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: IVD: 9e6aca98-2351-11e6-abef-000c29c66e3d // IVD: 4b925098-f6b1-42ef-a1d0-6f7cdce19847 // CNVD: CNVD-2015-01603 // VULHUB: VHN-79555 // JVNDB: JVNDB-2015-001703 // CNNVD: CNNVD-201503-128 // NVD: CVE-2015-1594

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-Other

Trust: 0.8

sources: JVNDB: JVNDB-2015-001703 // NVD: CVE-2015-1594

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201503-128

TYPE

Path traversal

Trust: 0.4

sources: IVD: 9e6aca98-2351-11e6-abef-000c29c66e3d // IVD: 4b925098-f6b1-42ef-a1d0-6f7cdce19847

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-001703

PATCH

title:SSA-451236url:http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-451236.pdf

Trust: 0.8

title:There are patches for search path vulnerabilities in many Siemens products.url:https://www.cnvd.org.cn/patchInfo/show/56192

Trust: 0.6

sources: CNVD: CNVD-2015-01603 // JVNDB: JVNDB-2015-001703

EXTERNAL IDS

db:NVDid:CVE-2015-1594

Trust: 3.5

db:SIEMENSid:SSA-451236

Trust: 2.3

db:CNNVDid:CNNVD-201503-128

Trust: 1.1

db:SECTRACKid:1032039

Trust: 1.1

db:CNVDid:CNVD-2015-01603

Trust: 1.0

db:JVNDBid:JVNDB-2015-001703

Trust: 0.8

db:IVDid:9E6ACA98-2351-11E6-ABEF-000C29C66E3D

Trust: 0.2

db:IVDid:4B925098-F6B1-42EF-A1D0-6F7CDCE19847

Trust: 0.2

db:VULHUBid:VHN-79555

Trust: 0.1

sources: IVD: 9e6aca98-2351-11e6-abef-000c29c66e3d // IVD: 4b925098-f6b1-42ef-a1d0-6f7cdce19847 // CNVD: CNVD-2015-01603 // VULHUB: VHN-79555 // JVNDB: JVNDB-2015-001703 // CNNVD: CNNVD-201503-128 // NVD: CVE-2015-1594

REFERENCES

url:http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-451236.pdf

Trust: 2.3

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-1594

Trust: 1.4

url:http://www.securitytracker.com/id/1032039

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-1594

Trust: 0.8

sources: CNVD: CNVD-2015-01603 // VULHUB: VHN-79555 // JVNDB: JVNDB-2015-001703 // CNNVD: CNNVD-201503-128 // NVD: CVE-2015-1594

SOURCES

db:IVDid:9e6aca98-2351-11e6-abef-000c29c66e3d
db:IVDid:4b925098-f6b1-42ef-a1d0-6f7cdce19847
db:CNVDid:CNVD-2015-01603
db:VULHUBid:VHN-79555
db:JVNDBid:JVNDB-2015-001703
db:CNNVDid:CNNVD-201503-128
db:NVDid:CVE-2015-1594

LAST UPDATE DATE

2024-08-14T13:47:44.834000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-01603date:2015-03-13T00:00:00
db:VULHUBid:VHN-79555date:2016-08-24T00:00:00
db:JVNDBid:JVNDB-2015-001703date:2015-03-11T00:00:00
db:CNNVDid:CNNVD-201503-128date:2015-03-09T00:00:00
db:NVDid:CVE-2015-1594date:2016-08-24T19:55:04.207

SOURCES RELEASE DATE

db:IVDid:9e6aca98-2351-11e6-abef-000c29c66e3ddate:2015-03-13T00:00:00
db:IVDid:4b925098-f6b1-42ef-a1d0-6f7cdce19847date:2015-03-13T00:00:00
db:CNVDid:CNVD-2015-01603date:2015-03-13T00:00:00
db:VULHUBid:VHN-79555date:2015-03-07T00:00:00
db:JVNDBid:JVNDB-2015-001703date:2015-03-11T00:00:00
db:CNNVDid:CNNVD-201503-128date:2015-03-09T00:00:00
db:NVDid:CVE-2015-1594date:2015-03-07T02:59:03.803