A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC STEP 7 (TIA Portal) V17 (All versions < V17 Update 2). An attacker could achieve privilege escalation on the web server of certain devices due to improper access control vulnerability in the engineering system software. The attacker needs to have direct access to the impacted web server.
Metrics
No CVSS v4.0
Attack Vector Local
Attack Complexity Low
Privileges Required Low
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
No CVSS v3.0
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
This CVE is not in the KEV list.
The EPSS score is 0.00038.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Siemens
Subscribe
|
Simatic S7-1200 Cpu
Subscribe
Simatic S7-1200 Cpu 1211c
Subscribe
Simatic S7-1200 Cpu 1212c
Subscribe
Simatic S7-1200 Cpu 1212fc
Subscribe
Simatic S7-1200 Cpu 1214 Fc
Subscribe
Simatic S7-1200 Cpu 1214c
Subscribe
Simatic S7-1200 Cpu 1214fc
Subscribe
Simatic S7-1200 Cpu 1215 Fc
Subscribe
Simatic S7-1200 Cpu 1215c
Subscribe
Simatic S7-1200 Cpu 1215fc
Subscribe
Simatic S7-1200 Cpu 1217c
Subscribe
Simatic S7-1500 Cpu
Subscribe
Simatic S7-1500 Cpu 1507s
Subscribe
Simatic S7-1500 Cpu 1507s F
Subscribe
Simatic S7-1500 Cpu 1508s
Subscribe
Simatic S7-1500 Cpu 1508s F
Subscribe
Simatic S7-1500 Cpu 1510sp
Subscribe
Simatic S7-1500 Cpu 1510sp-1
Subscribe
Simatic S7-1500 Cpu 1511-1
Subscribe
Simatic S7-1500 Cpu 1511-1 Pn
Subscribe
Simatic S7-1500 Cpu 1511c
Subscribe
Simatic S7-1500 Cpu 1511c-1
Subscribe
Simatic S7-1500 Cpu 1511f-1
Subscribe
Simatic S7-1500 Cpu 1511f-1 Pn
Subscribe
Simatic S7-1500 Cpu 1511t-1
Subscribe
Simatic S7-1500 Cpu 1511tf-1
Subscribe
Simatic S7-1500 Cpu 1512c
Subscribe
Simatic S7-1500 Cpu 1512c-1
Subscribe
Simatic S7-1500 Cpu 1512sp-1
Subscribe
Simatic S7-1500 Cpu 1512spf-1
Subscribe
Simatic S7-1500 Cpu 1513-1
Subscribe
Simatic S7-1500 Cpu 1513-1 Pn
Subscribe
Simatic S7-1500 Cpu 1513f-1
Subscribe
Simatic S7-1500 Cpu 1513f-1 Pn
Subscribe
Simatic S7-1500 Cpu 1513r-1
Subscribe
Simatic S7-1500 Cpu 1515-2
Subscribe
Simatic S7-1500 Cpu 1515-2 Pn
Subscribe
Simatic S7-1500 Cpu 1515f-2
Subscribe
Simatic S7-1500 Cpu 1515f-2 Pn
Subscribe
Simatic S7-1500 Cpu 1515r-2
Subscribe
Simatic S7-1500 Cpu 1515t-2
Subscribe
Simatic S7-1500 Cpu 1515tf-2
Subscribe
Simatic S7-1500 Cpu 1516-3
Subscribe
Simatic S7-1500 Cpu 1516-3 Dp
Subscribe
Simatic S7-1500 Cpu 1516-3 Pn
Subscribe
Simatic S7-1500 Cpu 1516-3 Pn\/dp
Subscribe
Simatic S7-1500 Cpu 1516f-3
Subscribe
Simatic S7-1500 Cpu 1516f-3 Pn\/dp
Subscribe
Simatic S7-1500 Cpu 1516pro-2
Subscribe
Simatic S7-1500 Cpu 1516pro F
Subscribe
Simatic S7-1500 Cpu 1516t-3
Subscribe
Simatic S7-1500 Cpu 1516tf-3
Subscribe
Simatic S7-1500 Cpu 1517-3
Subscribe
Simatic S7-1500 Cpu 1517-3 Dp
Subscribe
Simatic S7-1500 Cpu 1517-3 Pn
Subscribe
Simatic S7-1500 Cpu 1517-3 Pn\/dp
Subscribe
Simatic S7-1500 Cpu 1517f-3
Subscribe
Simatic S7-1500 Cpu 1517f-3 Pn\/dp
Subscribe
Simatic S7-1500 Cpu 1517tf-3
Subscribe
Simatic S7-1500 Cpu 1518
Subscribe
Simatic S7-1500 Cpu 1518-4
Subscribe
Simatic S7-1500 Cpu 1518-4 Dp
Subscribe
Simatic S7-1500 Cpu 1518-4 Pn
Subscribe
Simatic S7-1500 Cpu 1518-4 Pn\/dp
Subscribe
Simatic S7-1500 Cpu 1518-4 Pn\/dp Mfp
Subscribe
Simatic S7-1500 Cpu 1518f-4
Subscribe
Simatic S7-1500 Cpu 1518f-4 Pn\/dp
Subscribe
Simatic S7-1500 Cpu 1518hf-4
Subscribe
Simatic S7-1500 Cpu 1518t-4
Subscribe
Simatic S7-1500 Cpu 1518tf-4
Subscribe
Simatic Step 7
Subscribe
|
Configuration 1 [-]
| AND |
|
No data.
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-29017 | A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC STEP 7 (TIA Portal) V17 (All versions < V17 Update 2). An attacker could achieve privilege escalation on the web server of certain devices due to improper access control vulnerability in the engineering system software. The attacker needs to have direct access to the impacted web server. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-08-04T03:22:25.804Z
Reserved: 2021-10-06T00:00:00
Link: CVE-2021-42029
No data.
Status : Modified
Published: 2022-04-12T09:15:13.817
Modified: 2024-11-21T06:27:06.913
Link: CVE-2021-42029
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD