Access Control Flaw in SIMATIC S7-1200 and S7-200 SMART CPUs by Siemens
CVE-2019-13945
6.8MEDIUM
Key Information:
Summary
The identified vulnerability in Siemens SIMATIC S7-1200 and S7-200 SMART CPU families allows for unauthorized access during the boot-up process via the UART interface. This flaw can be exploited by individuals who have physical access to the devices, enabling them to gain additional diagnostic capabilities that could potentially compromise system integrity and security.
Affected Version(s)
SIMATIC S7-1200 CPU family (incl. SIPLUS variants) All versions
SIMATIC S7-1200 CPU family < V4.x (incl. SIPLUS variants) All versions
SIMATIC S7-1200 CPU family V4.x (incl. SIPLUS variants) All versions with Function State (FS) < 11
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved