CVE-2015-1356: Medium severity simatic step 7 vulnerability
Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 determines a user's privileges on the basis of project-file fields that lack integrity protection, which allows remote attackers to establish arbitrary authorization data via a modified file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1356?
CVE-2015-1356 has a medium severity rating due to its potential for unauthorized access by exploiting user privileges.
How do I fix CVE-2015-1356?
To fix CVE-2015-1356, upgrade Siemens SIMATIC STEP 7 to version 13 SP1 or later to ensure integrity protection.
What is the impact of CVE-2015-1356?
The impact of CVE-2015-1356 allows remote attackers to manipulate project-file fields, thereby gaining unauthorized access.
Who is affected by CVE-2015-1356?
CVE-2015-1356 affects users of Siemens SIMATIC STEP 7 versions prior to 13 SP1.
Can CVE-2015-1356 be exploited remotely?
Yes, CVE-2015-1356 can be exploited remotely by attackers to alter user authorization levels.