Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-37172


A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate against configured passwords when provisioned using TIA Portal V13. This could allow an attacker using TIA Portal V13 or later versions to bypass authentication and download arbitrary programs to the PLC. The vulnerability does not occur when TIA Portal V13 SP1 or any later version was used to provision the device.


Published

2021-08-10T11:15:09.280

Last Modified

2024-11-21T06:14:47.323

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-287
  • Type: Secondary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System siemens simatic_s7-1200_cpu_firmware 4.5.0 Yes
Hardware siemens cpu_1211c - No
Hardware siemens cpu_1212c - No
Hardware siemens cpu_1212fc - No
Hardware siemens cpu_1214c - No
Hardware siemens cpu_1214fc - No
Hardware siemens cpu_1215c - No
Hardware siemens cpu_1215fc - No
Hardware siemens cpu_1217c - No
Application siemens simatic_step_7_\(tia_portal\) ≤ 13.0 Yes

References