Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-2823


Siemens SIMATIC HMI Basic Panels 2nd Generation before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Professional before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Basic Panels 1st Generation (WinCC TIA Portal), SIMATIC HMI Mobile Panel 277 (WinCC TIA Portal), SIMATIC HMI Multi Panels (WinCC TIA Portal), and SIMATIC WinCC 7.x before 7.3 Upd4 allow remote attackers to complete authentication by leveraging knowledge of a password hash without knowledge of the associated password.


Published

2015-04-08T16:59:01.270

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application siemens wincc 7.0 Yes
Application siemens wincc 7.1 Yes
Application siemens wincc 7.2 Yes
Application siemens wincc 7.3 Yes
Application siemens wincc ≤ 13.0 Yes
Application siemens wincc ≤ 13.0 Yes
Hardware siemens simatic_hmi_basic_panels_generation_1 * No
Hardware siemens simatic_hmi_basic_panels_generation_2 * No
Hardware siemens simatic_hmi_comfort_panels * No
Hardware siemens simatic_hmi_mobile_panel_277 * No
Hardware siemens simatic_hmi_multi_panels * No

References