Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the affected system, to bypass the application-level authentication.
2017-02-22T02:59:00.153
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 9.0 (CRITICAL)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | siemens | simatic_logon | ≤ 1.5 | Yes |