Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2015-1355

Overview

Vulnerability Score 2.1 2.1
CVE Id CVE-2015-1355
Last Modified 18 Feb 2015 01:35:40
Published 17 Feb 2015 09:59:05
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2015-1355

Summary

Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes it easier for local users to determine cleartext passwords by reading a project file and conducting a brute-force attack.

Vulnerable Systems

Application

  • Siemens Simatic Step 7 13.0


References

CONFIRM - http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-234789.pdf


Last Updated: 27 May 2016 11:07:52