A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service of affected systems does not perform authentication in the default configuration. This could allow an unauthenticated remote attacker to send arbitrary messages to the service and thereby issue arbitrary requests in the affected system.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2022-07-12T10:06:30

Updated: 2024-08-04T04:17:24.864Z

Reserved: 2021-11-25T00:00:00

Link: CVE-2021-44222

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-07-12T10:15:10.050

Modified: 2022-07-15T19:01:31.317

Link: CVE-2021-44222

cve-icon Redhat

No data.