HIGH · 7.8

CVE-2021-42029

A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC STEP 7 (TIA Portal) V17 (All versions < V1...

Vulnerability Description

A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC STEP 7 (TIA Portal) V17 (All versions < V17 Update 2). An attacker could achieve privilege escalation on the web server of certain devices due to improper access control vulnerability in the engineering system software. The attacker needs to have direct access to the impacted web server.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SiemensSimatic Step 7>= 15, < 16
SiemensSimatic S7-1200 Cpu-
SiemensSimatic S7-1200 Cpu 1211C-
SiemensSimatic S7-1200 Cpu 1212C-
SiemensSimatic S7-1200 Cpu 1212Fc-
SiemensSimatic S7-1200 Cpu 1214 Fc-
SiemensSimatic S7-1200 Cpu 1214C-
SiemensSimatic S7-1200 Cpu 1214Fc-
SiemensSimatic S7-1200 Cpu 1215 Fc-
SiemensSimatic S7-1200 Cpu 1215C-
SiemensSimatic S7-1200 Cpu 1215Fc-
SiemensSimatic S7-1200 Cpu 1217C-
SiemensSimatic S7-1500 Cpu-
SiemensSimatic S7-1500 Cpu 1507S-
SiemensSimatic S7-1500 Cpu 1507S F-
SiemensSimatic S7-1500 Cpu 1508S-
SiemensSimatic S7-1500 Cpu 1508S F-
SiemensSimatic S7-1500 Cpu 1510Sp-
SiemensSimatic S7-1500 Cpu 1510Sp-1-
SiemensSimatic S7-1500 Cpu 1511-1-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-42029?

CVE-2021-42029 is a vulnerability with a CVSS score of 7.8 (HIGH). A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC STEP 7 (TIA Portal) V17 (All versions < V1...

How severe is CVE-2021-42029?

CVE-2021-42029 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-42029?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Simatic Step 7, Siemens Simatic S7-1200 Cpu, Siemens Simatic S7-1200 Cpu 1211C, Siemens Simatic S7-1200 Cpu 1212C, Siemens Simatic S7-1200 Cpu 1212Fc.