Privilege Escalation in Siemens SIMATIC STEP 7 Engineering Software
CVE-2021-42029
7.8HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 12 April 2022
Summary
A vulnerability has been identified in Siemens SIMATIC STEP 7 (TIA Portal) affecting versions V15, V16 prior to Update 5, and V17 prior to Update 2. This vulnerability allows an attacker with direct access to the impacted web server to escalate their privileges on the engineering system software. Improper access controls can enable malicious users to gain unauthorized access, posing significant security risks to affected systems.
Affected Version(s)
SIMATIC STEP 7 (TIA Portal) V15 All versions
SIMATIC STEP 7 (TIA Portal) V16 All versions < V16 Update 5
SIMATIC STEP 7 (TIA Portal) V17 All versions < V17 Update 2
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved