← Back

CVE-2021-40364

nvd nist
Published: Nov 9, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD (Secondary)

Description

A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC04), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (All versions < V16 Update 5), SIMATIC WinCC V17 (All versions < V17 Update 2), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 19), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 5). The affected systems store sensitive information in log files. An attacker with access to the log files could publicly expose the information or reuse it to develop further attacks on the system.

Affected (21)

2 products
Simatic Pcs 7
Simatic Wincc
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Siemens
Up to 8.2
From 9.0 to 9.1
Version 9.1
Siemens
Up to 7.4
Version 15
Version 16
Version 16 update1
Version 16 update2
Version 16 update3
Version 16 update4
Version 17
Version 17 update1
Version 7.5
Version 7.5 sp1
Version 7.5 sp1_update1
Version 7.5 sp1_update2
Version 7.5 sp2
Version 7.5 sp2_update1
Version 7.5 sp2_update2
Version 7.5 sp2_update3
Version 7.5 sp2_update4

References (2)

Source: productcert@siemens.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.