Privilege Escalation in Siemens SIMATIC STEP 7 Engineering Software
CVE-2021-42029 
7.8HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 12 April 2022
What is CVE-2021-42029?
A vulnerability has been identified in Siemens SIMATIC STEP 7 (TIA Portal) affecting versions V15, V16 prior to Update 5, and V17 prior to Update 2. This vulnerability allows an attacker with direct access to the impacted web server to escalate their privileges on the engineering system software. Improper access controls can enable malicious users to gain unauthorized access, posing significant security risks to affected systems.
Affected Version(s)
SIMATIC STEP 7 (TIA Portal) V15 All versions
SIMATIC STEP 7 (TIA Portal) V16 All versions < V16 Update 5
SIMATIC STEP 7 (TIA Portal) V17 All versions < V17 Update 2