CVE-2021-42029
published 2022-04-12CVE-2021-42029: A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.8th percentile
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC STEP 7 (TIA Portal) V17 (All versions < V17 Update 2). An attacker could achieve privilege escalation on the web server of certain devices due to improper access control vulnerability in the engineering system software. The attacker needs to have direct access to the impacted web server.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_step_7 | — | — |
| siemens | simatic_step_7 | — | — |
| siemens | simatic_step_7 | >= 15 < 16 | 16 |
| siemens | simatic_step_7_v15 | — | — |
| siemens | simatic_step_7_v16 | — | — |
| siemens | simatic_step_7_v17 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC STEP 7 (TIA Portal)
cisa_ics·2022-04-14·CVSS 7.8
[HIGH] Siemens SIMATIC STEP 7 (TIA Portal)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC STEP 7 (TIA Portal)
Last RevisedApril 14, 2022
Alert CodeICSA-22-104-14
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.4
- Vendor: Siemens
- Equipment: STEP 7 (TIA Portal)
- Vulnerability: Improper Access Control
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to achieve privilege escalation on the web server of certain devices configured by SIMATIC STEP 7 (TIA Portal) due to incorrect handling of the webserver’s user management configuration during downloading.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The followin
GHSA
GHSA-vp88-r9qc-vwrw: A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5),
ghsa_unreviewed·2022-04-13
CVE-2021-42029 [HIGH] CWE-269 GHSA-vp88-r9qc-vwrw: A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5),
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC STEP 7 (TIA Portal) V17 (All versions < V17 Update 2). An attacker could achieve privilege escalation on the web server of certain devices due to improper access control vulnerability in the engineering system software. The attacker needs to have direct access to the impacted web server.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-12
Published