Authentication Flaw in Siemens SIMATIC eaSie Core Package
CVE-2021-44222
9.1CRITICAL
What is CVE-2021-44222?
A significant authentication flaw has been discovered in the Siemens SIMATIC eaSie Core Package, where the default configuration of the MQTT service lacks authentication measures. This oversight could permit an unauthenticated remote attacker to send arbitrary messages to the service, potentially allowing them to execute unwanted commands and manipulate tasks within the affected system. For detailed remediation guidelines, refer to the official Siemens security advisory.
Affected Version(s)
SIMATIC eaSie Core Package All versions < V22.00