Privilege Escalation in Siemens SIMATIC STEP 7 Engineering Software
CVE-2021-42029

7.8HIGH

Summary

A vulnerability has been identified in Siemens SIMATIC STEP 7 (TIA Portal) affecting versions V15, V16 prior to Update 5, and V17 prior to Update 2. This vulnerability allows an attacker with direct access to the impacted web server to escalate their privileges on the engineering system software. Improper access controls can enable malicious users to gain unauthorized access, posing significant security risks to affected systems.

Affected Version(s)

SIMATIC STEP 7 (TIA Portal) V15 All versions

SIMATIC STEP 7 (TIA Portal) V16 All versions < V16 Update 5

SIMATIC STEP 7 (TIA Portal) V17 All versions < V17 Update 2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.