CVE-2015-1356

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
18/02/2015
Last modified:
12/04/2025

Description

Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 determines a user's privileges on the basis of project-file fields that lack integrity protection, which allows remote attackers to establish arbitrary authorization data via a modified file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:siemens:simatic_step_7:*:*:*:*:*:*:*:* 13.0 (including)