CVE-2015-1355: Low severity simatic step 7 vulnerability
Published Feb 18, 2015
·Updated
Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes it easier for local users to determine cleartext passwords by reading a project file and conducting a brute-force attack.
Affected Software
1 affected component
Siemens SIMATIC STEP 7<=13.0
Event History
Feb 18, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1355?
CVE-2015-1355 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-1355?
To mitigate CVE-2015-1355, upgrade to Siemens SIMATIC STEP 7 version 13 SP1 or later.
3
What problem does CVE-2015-1355 expose in Siemens products?
CVE-2015-1355 exposes Siemens SIMATIC STEP 7 to potential brute-force attacks due to a weak password-hash algorithm.
4
Who is affected by CVE-2015-1355?
Any user of Siemens SIMATIC STEP 7 versions prior to 13 SP1 is affected by CVE-2015-1355.
5
Is there a way to protect against CVE-2015-1355?
Users can protect against CVE-2015-1355 by ensuring they apply the necessary software updates and using strong passwords.