Vulnerability Description
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC STEP 7 (TIA Portal) V17 (All versions < V17 Update 2). An attacker could achieve privilege escalation on the web server of certain devices due to improper access control vulnerability in the engineering system software. The attacker needs to have direct access to the impacted web server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Simatic Step 7 | >= 15, < 16 |
| Siemens | Simatic S7-1200 Cpu | - |
| Siemens | Simatic S7-1200 Cpu 1211C | - |
| Siemens | Simatic S7-1200 Cpu 1212C | - |
| Siemens | Simatic S7-1200 Cpu 1212Fc | - |
| Siemens | Simatic S7-1200 Cpu 1214 Fc | - |
| Siemens | Simatic S7-1200 Cpu 1214C | - |
| Siemens | Simatic S7-1200 Cpu 1214Fc | - |
| Siemens | Simatic S7-1200 Cpu 1215 Fc | - |
| Siemens | Simatic S7-1200 Cpu 1215C | - |
| Siemens | Simatic S7-1200 Cpu 1215Fc | - |
| Siemens | Simatic S7-1200 Cpu 1217C | - |
| Siemens | Simatic S7-1500 Cpu | - |
| Siemens | Simatic S7-1500 Cpu 1507S | - |
| Siemens | Simatic S7-1500 Cpu 1507S F | - |
| Siemens | Simatic S7-1500 Cpu 1508S | - |
| Siemens | Simatic S7-1500 Cpu 1508S F | - |
| Siemens | Simatic S7-1500 Cpu 1510Sp | - |
| Siemens | Simatic S7-1500 Cpu 1510Sp-1 | - |
| Siemens | Simatic S7-1500 Cpu 1511-1 | - |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-350757.pdfPatchVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-350757.pdfPatchVendor Advisory
FAQ
What is CVE-2021-42029?
CVE-2021-42029 is a vulnerability with a CVSS score of 7.8 (HIGH). A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC STEP 7 (TIA Portal) V17 (All versions < V1...
How severe is CVE-2021-42029?
CVE-2021-42029 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-42029?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Simatic Step 7, Siemens Simatic S7-1200 Cpu, Siemens Simatic S7-1200 Cpu 1211C, Siemens Simatic S7-1200 Cpu 1212C, Siemens Simatic S7-1200 Cpu 1212Fc.