A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Users with elevated privileges to TIA-Portal and project data on the engineering station could possibly get privileged access on affected devices.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/94436 | third party advisory vdb entry |
https://ics-cert.us-cert.gov/advisories/ICSA-16-327-01 | |
http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-672373.pdf | patch vendor advisory |
https://cert-portal.siemens.com/productcert/pdf/ssa-672373.pdf |