A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC STEP 7 (TIA Portal) V17 (All versions < V17 Update 2). An attacker could achieve privilege escalation on the web server of certain devices due to improper access control vulnerability in the engineering system software. The attacker needs to have direct access to the impacted web server.

Project Subscriptions

Vendors Products
Siemens Subscribe
Simatic S7-1200 Cpu Subscribe
Simatic S7-1200 Cpu 1211c Subscribe
Simatic S7-1200 Cpu 1212c Subscribe
Simatic S7-1200 Cpu 1212fc Subscribe
Simatic S7-1200 Cpu 1214 Fc Subscribe
Simatic S7-1200 Cpu 1214c Subscribe
Simatic S7-1200 Cpu 1214fc Subscribe
Simatic S7-1200 Cpu 1215 Fc Subscribe
Simatic S7-1200 Cpu 1215c Subscribe
Simatic S7-1200 Cpu 1215fc Subscribe
Simatic S7-1200 Cpu 1217c Subscribe
Simatic S7-1500 Cpu Subscribe
Simatic S7-1500 Cpu 1507s Subscribe
Simatic S7-1500 Cpu 1507s F Subscribe
Simatic S7-1500 Cpu 1508s Subscribe
Simatic S7-1500 Cpu 1508s F Subscribe
Simatic S7-1500 Cpu 1510sp Subscribe
Simatic S7-1500 Cpu 1510sp-1 Subscribe
Simatic S7-1500 Cpu 1511-1 Subscribe
Simatic S7-1500 Cpu 1511-1 Pn Subscribe
Simatic S7-1500 Cpu 1511c Subscribe
Simatic S7-1500 Cpu 1511c-1 Subscribe
Simatic S7-1500 Cpu 1511f-1 Subscribe
Simatic S7-1500 Cpu 1511f-1 Pn Subscribe
Simatic S7-1500 Cpu 1511t-1 Subscribe
Simatic S7-1500 Cpu 1511tf-1 Subscribe
Simatic S7-1500 Cpu 1512c Subscribe
Simatic S7-1500 Cpu 1512c-1 Subscribe
Simatic S7-1500 Cpu 1512sp-1 Subscribe
Simatic S7-1500 Cpu 1512spf-1 Subscribe
Simatic S7-1500 Cpu 1513-1 Subscribe
Simatic S7-1500 Cpu 1513-1 Pn Subscribe
Simatic S7-1500 Cpu 1513f-1 Subscribe
Simatic S7-1500 Cpu 1513f-1 Pn Subscribe
Simatic S7-1500 Cpu 1513r-1 Subscribe
Simatic S7-1500 Cpu 1515-2 Subscribe
Simatic S7-1500 Cpu 1515-2 Pn Subscribe
Simatic S7-1500 Cpu 1515f-2 Subscribe
Simatic S7-1500 Cpu 1515f-2 Pn Subscribe
Simatic S7-1500 Cpu 1515r-2 Subscribe
Simatic S7-1500 Cpu 1515t-2 Subscribe
Simatic S7-1500 Cpu 1515tf-2 Subscribe
Simatic S7-1500 Cpu 1516-3 Subscribe
Simatic S7-1500 Cpu 1516-3 Dp Subscribe
Simatic S7-1500 Cpu 1516-3 Pn Subscribe
Simatic S7-1500 Cpu 1516-3 Pn\/dp Subscribe
Simatic S7-1500 Cpu 1516f-3 Subscribe
Simatic S7-1500 Cpu 1516f-3 Pn\/dp Subscribe
Simatic S7-1500 Cpu 1516pro-2 Subscribe
Simatic S7-1500 Cpu 1516pro F Subscribe
Simatic S7-1500 Cpu 1516t-3 Subscribe
Simatic S7-1500 Cpu 1516tf-3 Subscribe
Simatic S7-1500 Cpu 1517-3 Subscribe
Simatic S7-1500 Cpu 1517-3 Dp Subscribe
Simatic S7-1500 Cpu 1517-3 Pn Subscribe
Simatic S7-1500 Cpu 1517-3 Pn\/dp Subscribe
Simatic S7-1500 Cpu 1517f-3 Subscribe
Simatic S7-1500 Cpu 1517f-3 Pn\/dp Subscribe
Simatic S7-1500 Cpu 1517tf-3 Subscribe
Simatic S7-1500 Cpu 1518 Subscribe
Simatic S7-1500 Cpu 1518-4 Subscribe
Simatic S7-1500 Cpu 1518-4 Dp Subscribe
Simatic S7-1500 Cpu 1518-4 Pn Subscribe
Simatic S7-1500 Cpu 1518-4 Pn\/dp Subscribe
Simatic S7-1500 Cpu 1518-4 Pn\/dp Mfp Subscribe
Simatic S7-1500 Cpu 1518f-4 Subscribe
Simatic S7-1500 Cpu 1518f-4 Pn\/dp Subscribe
Simatic S7-1500 Cpu 1518hf-4 Subscribe
Simatic S7-1500 Cpu 1518t-4 Subscribe
Simatic S7-1500 Cpu 1518tf-4 Subscribe
Simatic Step 7 Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-29017 A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC STEP 7 (TIA Portal) V17 (All versions < V17 Update 2). An attacker could achieve privilege escalation on the web server of certain devices due to improper access control vulnerability in the engineering system software. The attacker needs to have direct access to the impacted web server.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2024-08-04T03:22:25.804Z

Reserved: 2021-10-06T00:00:00

Link: CVE-2021-42029

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-12T09:15:13.817

Modified: 2024-11-21T06:27:06.913

Link: CVE-2021-42029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses