Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-37172

Опубликовано: 10 авг. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate against configured passwords when provisioned using TIA Portal V13. This could allow an attacker using TIA Portal V13 or later versions to bypass authentication and download arbitrary programs to the PLC. The vulnerability does not occur when TIA Portal V13 SP1 or any later version was used to provision the device.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:siemens:simatic_s7-1200_cpu_firmware:4.5.0:*:*:*:*:*:*:*

Одно из

cpe:2.3:h:siemens:cpu_1211c:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cpu_1212c:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cpu_1212fc:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cpu_1214c:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cpu_1214fc:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cpu_1215c:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cpu_1215fc:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cpu_1217c:-:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:siemens:simatic_step_7_\(tia_portal\):*:*:*:*:*:*:*:*
Версия до 13.0 (включая)

EPSS

Процентиль: 41%
0.00186
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-287
CWE-287

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate against configured passwords when provisioned using TIA Portal V13. This could allow an attacker using TIA Portal V17 or later versions to bypass authentication and download arbitrary programs to the PLC. The vulnerability does not occur when TIA Portal V13 SP1 or any later version was used to provision the device.

EPSS

Процентиль: 41%
0.00186
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-287
CWE-287