CVE-2015-1602
published 2015-04-06CVE-2015-1602: Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data within project files, which makes it easier for local users to…
PriorityP48low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.37%
28.8th percentile
Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data within project files, which makes it easier for local users to determine cleartext (1) protection-level passwords or (2) web-server passwords by leveraging the ability to read these files.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_step_7 | <= 13.0 | — |
| siemens | simatic_step_7 | — | — |
| siemens | simatic_step_7 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC STEP 7 TIA Portal Vulnerabilities (Update A)
cisa_ics·2015-02-19
Siemens SIMATIC STEP 7 TIA Portal Vulnerabilities (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC STEP 7 TIA Portal Vulnerabilities (Update A)
Last RevisedAugust 27, 2018
Alert CodeICSA-15-050-01A
## OVERVIEW
This updated advisory is a follow-up to the original advisory titled ICSA-15-050-01 Siemens SIMATIC STEP 7 TIA Portal Vulnerabilities that was published February 19, 2015, on the NCCIC/ICS-CERT web site.
Siemens has identified two vulnerabilities in its SIMATIC STEP 7 (TIA Portal). Siemens has produced a patch that mitigates these vulnerabilities. These vulnerabilities were initially disclosed to Siemens by the Quarkslab team and Dmitry Sklyarov with PT
GHSA
GHSA-xrc4-pj8p-r2hh: Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data within project files, which makes it easier for local
ghsa_unreviewed·2022-05-17
CVE-2015-1602 [LOW] CWE-200 GHSA-xrc4-pj8p-r2hh: Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data within project files, which makes it easier for local
Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data within project files, which makes it easier for local users to determine cleartext (1) protection-level passwords or (2) web-server passwords by leveraging the ability to read these files.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-04-06
Published