Vulnerability CVE-2015-1358


Published: 2015-02-17   Modified: 2015-02-18

Description:
The remote-management module in the (1) Multi Panels, (2) Comfort Panels, and (3) RT Advanced functionality in Siemens SIMATIC WinCC (TIA Portal) before 13 SP1 and in the (4) panels and (5) runtime functionality in SIMATIC WinCC flexible before 2008 SP3 Up7 does not properly encrypt credentials in transit, which makes it easier for remote attackers to determine cleartext credentials by sniffing the network and conducting a decryption attack.

See advisories in our WLB2 database:
Topic
Author
Date
High
Siemens SIMATIC TIA Portal (Step 7/WinCC) fixes
SCADA StrangeLov...
17.02.2015

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Siemens -> Wincc 

 References:
http://www.securityfocus.com/bid/72625
http://www.securitytracker.com/id/1036090
http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-526760.pdf
http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-543623.pdf
https://ics-cert.us-cert.gov/advisories/ICSA-16-161-02

Copyright 2024, cxsecurity.com

 

Back to Top