PT-2018-2166 · Siemens · Simatic Step 7
Published
2018-11-13
·
Updated
2019-10-09
·
CVE-2018-13811
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SIMATIC STEP 7 (TIA Portal) versions prior to V15.1
Description
A vulnerability has been identified that could allow an attacker to access a project file and reconstruct passwords due to password hashes with insufficient computational effort. The issue can be exploited by an attacker with local access to the project file, requiring no user interaction. This could enable the attacker to obtain certain passwords from the project. At the time of advisory publication, no public exploitation of this issue was known.
Recommendations
For versions prior to V15.1, update to version V15.1 or later to resolve the issue. As a temporary workaround, consider restricting access to project files to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simatic Step 7