CVE-2012-3015 Information

Description

Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1 as used in SIMATIC PCS7 7.1 SP3 and earlier and other products allows local users to gain privileges via a Trojan horse DLL in a STEP7 project folder.

Reference

http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-110665.pdf http://www.us-cert.gov/control_systems/pdf/ICSA-12-205-02.pdf

Share on: