Access Control Flaw in SIMATIC S7-1200 and S7-200 SMART CPUs by Siemens
CVE-2019-13945

6.8MEDIUM

Summary

The identified vulnerability in Siemens SIMATIC S7-1200 and S7-200 SMART CPU families allows for unauthorized access during the boot-up process via the UART interface. This flaw can be exploited by individuals who have physical access to the devices, enabling them to gain additional diagnostic capabilities that could potentially compromise system integrity and security.

Affected Version(s)

SIMATIC S7-1200 CPU family (incl. SIPLUS variants) All versions

SIMATIC S7-1200 CPU family < V4.x (incl. SIPLUS variants) All versions

SIMATIC S7-1200 CPU family V4.x (incl. SIPLUS variants) All versions with Function State (FS) < 11

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.