SB2016101306 - Information disclosure in Siemens Automation License Manager



SB2016101306 - Information disclosure in Siemens Automation License Manager

Published: October 13, 2016 Updated: October 14, 2016

Security Bulletin ID SB2016101306
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2016-8565)

The vulnerability allows a remote unauthenticated user to read and modify important data the target system.
The weakness is due to improper input validation. By sending a specially crafted packets of upload files, attackers can create and delete directories or move existing files on the hard disk.
Successful exploitation of the vulnerability results in disclosure and modification of information.

Remediation

Install update from vendor's website.