CVE-2021-37172
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate against configured passwords when provisioned using TIA Portal V13. This could allow an attacker using TIA Portal V13 or later versions to bypass authentication and download arbitrary programs to the PLC. The vulnerability does not occur when TIA Portal V13 SP1 or any later version was used to provision the device.
Se ha identificado una vulnerabilidad en la familia de CPUs SIMATIC S7-1200 (Incluyendo las variantes SIPLUS) (V4.5.0). Los dispositivos afectados no se autentican con las contraseñas configuradas cuando se aprovisionan con TIA Portal V13. Esto podría permitir a un atacante que utilice TIA Portal V13 o versiones posteriores eludir la autenticación y descargar programas arbitrarios en el PLC. La vulnerabilidad no se produce cuando se utiliza TIA Portal V13 SP1 o cualquier versión posterior para aprovisionar el dispositivo
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-07-21 CVE Reserved
- 2021-08-10 CVE Published
- 2024-04-25 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-830194.pdf | 2022-07-01 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Simatic S7-1200 Cpu Firmware Search vendor "Siemens" for product "Simatic S7-1200 Cpu Firmware" | 4.5.0 Search vendor "Siemens" for product "Simatic S7-1200 Cpu Firmware" and version "4.5.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Cpu 1211c Search vendor "Siemens" for product "Cpu 1211c" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic S7-1200 Cpu Firmware Search vendor "Siemens" for product "Simatic S7-1200 Cpu Firmware" | 4.5.0 Search vendor "Siemens" for product "Simatic S7-1200 Cpu Firmware" and version "4.5.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Cpu 1212c Search vendor "Siemens" for product "Cpu 1212c" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic S7-1200 Cpu Firmware Search vendor "Siemens" for product "Simatic S7-1200 Cpu Firmware" | 4.5.0 Search vendor "Siemens" for product "Simatic S7-1200 Cpu Firmware" and version "4.5.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Cpu 1212fc Search vendor "Siemens" for product "Cpu 1212fc" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic S7-1200 Cpu Firmware Search vendor "Siemens" for product "Simatic S7-1200 Cpu Firmware" | 4.5.0 Search vendor "Siemens" for product "Simatic S7-1200 Cpu Firmware" and version "4.5.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Cpu 1214c Search vendor "Siemens" for product "Cpu 1214c" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic S7-1200 Cpu Firmware Search vendor "Siemens" for product "Simatic S7-1200 Cpu Firmware" | 4.5.0 Search vendor "Siemens" for product "Simatic S7-1200 Cpu Firmware" and version "4.5.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Cpu 1214fc Search vendor "Siemens" for product "Cpu 1214fc" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic S7-1200 Cpu Firmware Search vendor "Siemens" for product "Simatic S7-1200 Cpu Firmware" | 4.5.0 Search vendor "Siemens" for product "Simatic S7-1200 Cpu Firmware" and version "4.5.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Cpu 1215c Search vendor "Siemens" for product "Cpu 1215c" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic S7-1200 Cpu Firmware Search vendor "Siemens" for product "Simatic S7-1200 Cpu Firmware" | 4.5.0 Search vendor "Siemens" for product "Simatic S7-1200 Cpu Firmware" and version "4.5.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Cpu 1215fc Search vendor "Siemens" for product "Cpu 1215fc" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic S7-1200 Cpu Firmware Search vendor "Siemens" for product "Simatic S7-1200 Cpu Firmware" | 4.5.0 Search vendor "Siemens" for product "Simatic S7-1200 Cpu Firmware" and version "4.5.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Cpu 1217c Search vendor "Siemens" for product "Cpu 1217c" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Step 7 \(tia Portal\) Search vendor "Siemens" for product "Simatic Step 7 \(tia Portal\)" | <= 13.0 Search vendor "Siemens" for product "Simatic Step 7 \(tia Portal\)" and version " <= 13.0" | - |
Affected
|