Authentication Vulnerability in Siemens SIMATIC Process Historian
CVE-2021-27395
8.1HIGH
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 12 October 2021
What is CVE-2021-27395?
A significant vulnerability exists in Siemens SIMATIC Process Historian versions, where a critical interface lacks proper authentication. This flaw can be exploited by unauthorized users to inject, alter, or erase vital data, posing a serious risk to the integrity and reliability of data stored in these systems. Organizations utilizing these products should assess their security posture and apply necessary updates to mitigate potential exploitation.
Affected Version(s)
SIMATIC Process Historian 2013 and earlier All versions
SIMATIC Process Historian 2014 All versions < SP3 Update 6
SIMATIC Process Historian 2019 All versions