← Back

CVE-2015-1356

nvd nist
Published: Feb 18, 2015Modified: May 6, 2026

JSON object

Loading...
4.4
Vector
AV:L/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 3.4 / Impact: 6.4
Source: NVD

Description

Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 determines a user's privileges on the basis of project-file fields that lack integrity protection, which allows remote attackers to establish arbitrary authorization data via a modified file.

Affected (1)

1 product
Simatic Step 7
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 13.0

Related CWEs

Timeline

No history available yet.