PT-2021-7272 · Siemens · Simatic Step 7

Published

2021-10-06

·

Updated

2022-08-09

·

CVE-2021-42029

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SIMATIC STEP 7 (TIA Portal) V15 (All versions) SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5) SIMATIC STEP 7 (TIA Portal) V17 (All versions < V17 Update 2)
Description A vulnerability has been identified due to improper access control in the engineering system software, allowing an attacker to achieve privilege escalation on the web server of certain devices. The attacker needs to have direct access to the impacted web server.
Recommendations For SIMATIC STEP 7 (TIA Portal) V15, update to a version that includes the necessary security fixes. For SIMATIC STEP 7 (TIA Portal) V16, update to V16 Update 5 or later. For SIMATIC STEP 7 (TIA Portal) V17, update to V17 Update 2 or later. As a temporary workaround, consider restricting access to the web server to minimize the risk of exploitation.

Fix

Improper Access Control

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2022-04783
CVE-2021-42029

Affected Products

Simatic Step 7