Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-13811

Опубликовано: 13 дек. 2018
Источник: nvd
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All Versions < V15.1). Password hashes with insufficient computational effort could allow an attacker to access to a project file and reconstruct passwords. The vulnerability could be exploited by an attacker with local access to the project file. No user interaction is required to exploit the vulnerability. The vulnerability could allow the attacker to obtain certain passwords from the project. At the time of advisory publication no public exploitation of this vulnerability was known.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:siemens:simatic_step_7_\(tia_portal\):*:*:*:*:*:*:*:*
Версия до 15.1 (исключая)

EPSS

Процентиль: 7%
0.00028
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-916
CWE-200

Связанные уязвимости

CVSS3: 5.5
github
больше 3 лет назад

A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All Versions < V15.1). Password hashes with insufficient computational effort could allow an attacker to access to a project file and reconstruct passwords. The vulnerability could be exploited by an attacker with local access to the project file. No user interaction is required to exploit the vulnerability. The vulnerability could allow the attacker to obtain certain passwords from the project. At the time of advisory publication no public exploitation of this vulnerability was known.

CVSS3: 4
fstec
около 7 лет назад

Уязвимость микропрограммного обеспечения программируемых логических контроллеров Siemens SIMATIC STEP 7 (TIA Portal), связанная с недостаточной защищенностью хранилища учетных данных, позволяющая нарушителю воcстанавливать пароли

EPSS

Процентиль: 7%
0.00028
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-916
CWE-200