The privilege escalation flaw, tracked CVE-2016-7165, was reported to Siemens by WATERSURE and KIANDRA IT. The flaw could be exploited by attackers to escalate their privileges if the flawed products are not installed under the default path. It affects several products, including Siemens SCADA systems, distributed control systems (DCS) and engineering tools and simulators. The US ICS-CERT has published its annual vulnerability coordination report for the fiscal year 2015.”]
Source: http://securityaffairs.co/wordpress/53266/security/cve-2016-7165-siemens.html

