CVE-2015-2823
Summary
| CVE | CVE-2015-2823 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-04-08 16:59:01 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Siemens SIMATIC HMI Basic Panels 2nd Generation before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Professional before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Basic Panels 1st Generation (WinCC TIA Portal), SIMATIC HMI Mobile Panel 277 (WinCC TIA Portal), SIMATIC HMI Multi Panels (WinCC TIA Portal), and SIMATIC WinCC 7.x before 7.3 Upd4 allow remote attackers to complete authentication by leveraging knowledge of a password hash without knowledge of the associated password. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Siemens | Simatic Hmi Basic Panels Generation 1 | All | All | All | All |
| Hardware | Siemens | Simatic Hmi Basic Panels Generation 2 | All | All | All | All |
| Hardware | Siemens | Simatic Hmi Comfort Panels | All | All | All | All |
| Hardware | Siemens | Simatic Hmi Mobile Panel 277 | All | All | All | All |
| Hardware | Siemens | Simatic Hmi Multi Panels | All | All | All | All |
| Application | Siemens | Wincc | 7.0 | All | All | All |
| Application | Siemens | Wincc | 7.1 | All | All | All |
| Application | Siemens | Wincc | 7.2 | All | All | All |
| Application | Siemens | Wincc | 7.3 | All | All | All |
| Application | Siemens | Wincc | All | sp1 | All | All |
| Application | Siemens | Wincc | All | sp1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cert-portal.siemens.com/productcert/pdf/ssa-487246.pdf | af854a3a-2127-422b-91ae-364da2661108 | cert-portal.siemens.com | |
| Siemens | af854a3a-2127-422b-91ae-364da2661108 | www.siemens.com | Patch, Vendor Advisory |
| Multiple Siemens SIMATIC Products CVE-2015-2823 Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590608 Siemens SIMATIC HMI Devices (Update E) Multiple Vulnerabilities (ICSA-15-099-01E)