Risk Scores
CVSS v3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SIMATIC S7-1200 CPU family (incl. SIPLUS variants) |
Timeline
- CVE Published
SIMATIC S7-1200 PLC, version V4.5.0 fails to authenticate against configured passwords when the affected device was provisioned using TIA Portal V13. This could allow an attacker using TIA Portal V13 or later versions to bypass authentication and download arbitrary programs to the PLC. Siemens has released an update for SIMATIC S7-1200 and recommends to update to the latest version.
| Vendor | Product | Versions |
|---|---|---|
| SIMATIC S7-1200 CPU family (incl. SIPLUS variants) |