First published: Wed Feb 18 2015(Updated: )
Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 determines a user's privileges on the basis of project-file fields that lack integrity protection, which allows remote attackers to establish arbitrary authorization data via a modified file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SIMATIC STEP 7 | <=13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1356 has a medium severity rating due to its potential for unauthorized access by exploiting user privileges.
To fix CVE-2015-1356, upgrade Siemens SIMATIC STEP 7 to version 13 SP1 or later to ensure integrity protection.
The impact of CVE-2015-1356 allows remote attackers to manipulate project-file fields, thereby gaining unauthorized access.
CVE-2015-1356 affects users of Siemens SIMATIC STEP 7 versions prior to 13 SP1.
Yes, CVE-2015-1356 can be exploited remotely by attackers to alter user authorization levels.