siemens simatic-step-7-tia-portal CVE-2021-37172 is a vulnerability in Siemens Simatic Step 7 Tia Portal
Published on August 10, 2021

A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate against configured passwords when provisioned using TIA Portal V13. This could allow an attacker using TIA Portal V13 or later versions to bypass authentication and download arbitrary programs to the PLC. The vulnerability does not occur when TIA Portal V13 SP1 or any later version was used to provision the device.

NVD

Weakness Type

What is an authentification Vulnerability?

When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.

CVE-2021-37172 has been classified to as an authentification vulnerability or weakness.


Products Associated with CVE-2021-37172

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2021-37172 are published in Siemens Simatic Step 7 Tia Portal:

 

Affected Versions

Siemens SIMATIC S7-1200 CPU family (incl. SIPLUS variants) Version V4.5.0 is affected by CVE-2021-37172

Exploit Probability

EPSS
0.19%
Percentile
40.33%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.