Authentication Flaw in Siemens SIMATIC eaSie Core Package
CVE-2021-44222
9.1CRITICAL
Summary
A significant authentication flaw has been discovered in the Siemens SIMATIC eaSie Core Package, where the default configuration of the MQTT service lacks authentication measures. This oversight could permit an unauthenticated remote attacker to send arbitrary messages to the service, potentially allowing them to execute unwanted commands and manipulate tasks within the affected system. For detailed remediation guidelines, refer to the official Siemens security advisory.
Affected Version(s)
SIMATIC eaSie Core Package All versions < V22.00
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved