A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service of affected systems does not perform authentication in the default configuration. This could allow an unauthenticated remote attacker to send arbitrary messages to the service and thereby issue arbitrary requests in the affected system.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: siemens
Published: 2022-07-12T10:06:30
Updated: 2024-08-04T04:17:24.864Z
Reserved: 2021-11-25T00:00:00
Link: CVE-2021-44222
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-07-12T10:15:10.050
Modified: 2024-11-21T06:30:36.823
Link: CVE-2021-44222
Redhat
No data.