siemens tia-administrator CVE-2019-10915 is a vulnerability in Siemens Tia Administrator
Published on July 11, 2019

A vulnerability has been identified in TIA Administrator (All versions < V1.0 SP1 Upd1). The integrated configuration web application (TIA Administrator) allows to execute certain application commands without proper authentication. The vulnerability could be exploited by an attacker with local access to the affected system. Successful exploitation requires no privileges and no user interaction. An attacker could use the vulnerability to compromise confidentiality and integrity and availability of the affected system. At the time of advisory publication no public exploitation of this security vulnerability was known.

NVD

Weakness Type

Missing Authentication for Critical Function

The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.


Products Associated with CVE-2019-10915

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2019-10915 are published in Siemens Tia Administrator:

 

Affected Versions

Siemens AG TIA Administrator Version All versions < V1.0 SP1 Upd1 is affected by CVE-2019-10915

Exploit Probability

EPSS
5.86%
Percentile
90.35%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.