Siemens SICAM PAS before 8.07 does not properly restrict password data in the database, which makes it easier for local users to calculate passwords by leveraging unspecified database privileges.Referenceshttps://ics-cert.us-cert.gov/advisories/ICSA-16-182-02http://www.securityfocus.com/bid/91525http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-444217.pdf