Web API Authentication Bypass in SIMATIC Devices by Siemens
CVE-2022-33138

7.5HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
12 July 2022

Summary

A security issue has been discovered in various Siemens SIMATIC products, where specific web API endpoints lack proper authentication. This vulnerability enables an unauthenticated remote attacker to read and download data from the affected devices. It impacts multiple versions of SIMATIC MV540, MV550, and MV560 series, potentially exposing sensitive information and leading to serious security concerns if not addressed promptly.

Affected Version(s)

SIMATIC MV540 H All versions < V3.3

SIMATIC MV540 S All versions < V3.3

SIMATIC MV550 H All versions < V3.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.