Authentication Flaw in Siemens SIMATIC eaSie Core Package
CVE-2021-44222

9.1CRITICAL

Key Information:

Vendor
Siemens
Vendor
CVE Published:
12 July 2022

Summary

A significant authentication flaw has been discovered in the Siemens SIMATIC eaSie Core Package, where the default configuration of the MQTT service lacks authentication measures. This oversight could permit an unauthenticated remote attacker to send arbitrary messages to the service, potentially allowing them to execute unwanted commands and manipulate tasks within the affected system. For detailed remediation guidelines, refer to the official Siemens security advisory.

Affected Version(s)

SIMATIC eaSie Core Package All versions < V22.00

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.