CVE-2015-1601: Medium severity simatic step 7 vulnerability
Published Apr 6, 2015
·Updated
Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 allows man-in-the-middle attackers to obtain sensitive information or modify transmitted data via unspecified vectors.
Affected Software
3 affected components
Siemens SIMATIC STEP 7<=13
Siemens SIMATIC STEP 7=12
Siemens SIMATIC STEP 7=13
Remediation
Event History
Apr 6, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1601?
CVE-2015-1601 has a medium to high severity rating due to the potential for man-in-the-middle attacks.
2
How do I fix CVE-2015-1601?
To mitigate CVE-2015-1601, update Siemens SIMATIC STEP 7 to version 13 SP1 Update 1 or later.
3
What types of attacks are possible with CVE-2015-1601?
CVE-2015-1601 allows attackers to intercept and modify sensitive information transmitted between systems.
4
Which versions of Siemens SIMATIC STEP 7 are affected by CVE-2015-1601?
CVE-2015-1601 affects Siemens SIMATIC STEP 7 versions 12 and 13 before 13 SP1 Update 1.
5
Is there a workaround for CVE-2015-1601?
There are no specific workarounds for CVE-2015-1601; applying the security update is recommended for protection.