CVE-2021-42029: High severity simatic step 7 vulnerability
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC STEP 7 (TIA Portal) V17 (All versions < V17 Update 2). An attacker could achieve privilege escalation on the web server of certain devices due to improper access control vulnerability in the engineering system software. The attacker needs to have direct access to the impacted web server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42029?
CVE-2021-42029 has been assigned a medium severity rating due to its potential for privilege escalation.
How do I fix CVE-2021-42029?
To remediate CVE-2021-42029, update your SIMATIC STEP 7 (TIA Portal) to version 16 Update 5 or later, or to version 17 Update 2 or later.
Which versions are affected by CVE-2021-42029?
CVE-2021-42029 affects SIMATIC STEP 7 (TIA Portal) versions 15, and versions 16 before Update 5, as well as versions 17 before Update 2.
What are the potential impacts of CVE-2021-42029?
CVE-2021-42029 could allow an attacker to gain unauthorized access and perform actions at a higher privilege level on the web server of affected devices.
Are there any workarounds for CVE-2021-42029?
Temporary mitigation for CVE-2021-42029 involves limiting access to the web server and implementing network segmentation controls.