Password Vulnerability in SIMATIC STEP 7 by Siemens
CVE-2018-13811
5.5MEDIUM
What is CVE-2018-13811?
A security flaw has been detected in SIMATIC STEP 7 (TIA Portal) affecting all versions prior to V15.1. This issue arises from the use of insufficient computational efforts for password hashing, allowing an attacker with local access to a project file to reconstruct passwords easily. Notably, no user interaction is necessary for exploitation, which heightens the risk of unauthorized access to sensitive project files. As of the advisory's release, there has been no evidence of public exploitation of this flaw, but its potential impact could lead to serious security breaches.
Affected Version(s)
SIMATIC STEP 7 (TIA Portal) SIMATIC STEP 7 (TIA Portal) : All Versions < V15.1