CVE Vulnerabilities

CVE-2015-1356

Published: Feb 18, 2015 | Modified: Feb 18, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 determines a users privileges on the basis of project-file fields that lack integrity protection, which allows remote attackers to establish arbitrary authorization data via a modified file.

Affected Software

Name Vendor Start Version End Version
Simatic_step_7 Siemens * 13.0 (including)

References