Siemens Simatic Step 7 vulnerabilities
24 known vulnerabilities affecting siemens/simatic_step_7.
Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8MEDIUM13LOW3
Vulnerabilities
Page 2 of 2
CVE-2015-1594MEDIUMCVSS 6.9≤ 5.5v5.52015-03-07
CVE-2015-1594 [MEDIUM] CVE-2015-1594: Untrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0
Untrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0 SP4 Upd9 and 8.1 before Upd1; SIMATIC STEP 7 before 5.5 SP1 HF2, 5.5 SP2 before HF7, 5.5 SP3, and 5.5 SP4 before HF4; SIMOTION Scout before 4.4; and STARTER before 4.4 HF3 allows local users to gain privileges via a Trojan horse application file.
nvd
CVE-2015-1356MEDIUMCVSS 4.4≤ 13.02015-02-18
CVE-2015-1356 [MEDIUM] CWE-264 CVE-2015-1356: Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 determines a user's privileges on the basis of pro
Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 determines a user's privileges on the basis of project-file fields that lack integrity protection, which allows remote attackers to establish arbitrary authorization data via a modified file.
nvd
CVE-2015-1355LOWCVSS 2.1≤ 13.02015-02-18
CVE-2015-1355 [LOW] CWE-310 CVE-2015-1355: Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes i
Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes it easier for local users to determine cleartext passwords by reading a project file and conducting a brute-force attack.
nvd
CVE-2012-3015MEDIUMCVSS 6.9≤ 5.52012-07-26
CVE-2012-3015 [MEDIUM] CVE-2012-3015: Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7
Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7 7.1 SP3 and earlier and other products, allows local users to gain privileges via a Trojan horse DLL in a STEP7 project folder.
nvd
← Previous2 / 2