CVE-2015-2823
Summary
| CVE | CVE-2015-2823 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-04-08 16:59:00 UTC |
| Updated | 2016-11-28 19:21:00 UTC |
| Description | Siemens SIMATIC HMI Basic Panels 2nd Generation before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Professional before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Basic Panels 1st Generation (WinCC TIA Portal), SIMATIC HMI Mobile Panel 277 (WinCC TIA Portal), SIMATIC HMI Multi Panels (WinCC TIA Portal), and SIMATIC WinCC 7.x before 7.3 Upd4 allow remote attackers to complete authentication by leveraging knowledge of a password hash without knowledge of the associated password. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Siemens | Simatic Hmi Basic Panels Generation 1 | All | All | All | All |
| Hardware | Siemens | Simatic Hmi Basic Panels Generation 1 | All | All | All | All |
| Hardware | Siemens | Simatic Hmi Basic Panels Generation 2 | All | All | All | All |
| Hardware | Siemens | Simatic Hmi Basic Panels Generation 2 | All | All | All | All |
| Hardware | Siemens | Simatic Hmi Comfort Panels | All | All | All | All |
| Hardware | Siemens | Simatic Hmi Comfort Panels | All | All | All | All |
| Hardware | Siemens | Simatic Hmi Mobile Panel 277 | All | All | All | All |
| Hardware | Siemens | Simatic Hmi Mobile Panel 277 | All | All | All | All |
| Hardware | Siemens | Simatic Hmi Multi Panels | All | All | All | All |
| Hardware | Siemens | Simatic Hmi Multi Panels | All | All | All | All |
| Application | Siemens | Wincc | 7.0 | All | All | All |
| Application | Siemens | Wincc | 7.1 | All | All | All |
| Application | Siemens | Wincc | 7.2 | All | All | All |
| Application | Siemens | Wincc | 7.3 | All | All | All |
| Application | Siemens | Wincc | 7.0 | All | All | All |
| Application | Siemens | Wincc | 7.1 | All | All | All |
| Application | Siemens | Wincc | 7.2 | All | All | All |
| Application | Siemens | Wincc | 7.3 | All | All | All |
| Application | Siemens | Wincc | All | sp1 | All | All |
| Application | Siemens | Wincc | All | sp1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Siemens SIMATIC Products CVE-2015-2823 Authentication Bypass Vulnerability | BID | www.securityfocus.com | |
| cert-portal.siemens.com/productcert/pdf/ssa-487246.pdf | CONFIRM | cert-portal.siemens.com | |
| Siemens | CONFIRM | www.siemens.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590608 Siemens SIMATIC HMI Devices (Update E) Multiple Vulnerabilities (ICSA-15-099-01E)