Authentication Vulnerability in Siemens SIMATIC Process Historian
CVE-2021-27395
8.1HIGH
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 12 October 2021
Summary
A significant vulnerability exists in Siemens SIMATIC Process Historian versions, where a critical interface lacks proper authentication. This flaw can be exploited by unauthorized users to inject, alter, or erase vital data, posing a serious risk to the integrity and reliability of data stored in these systems. Organizations utilizing these products should assess their security posture and apply necessary updates to mitigate potential exploitation.
Affected Version(s)
SIMATIC Process Historian 2013 and earlier All versions
SIMATIC Process Historian 2014 All versions < SP3 Update 6
SIMATIC Process Historian 2019 All versions
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved