CVE-2021-40363
Summary
| CVE | CVE-2021-40363 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-09 16:15:00 UTC |
| Updated | 2022-10-06 16:46:00 UTC |
| Description | A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (All versions < V16 Update 5), SIMATIC WinCC V17 (All versions < V17 Update 2), SIMATIC WinCC V17 (All versions <= V17 Update 4), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 19), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 6). The affected component stores the credentials of a local system account in a potentially publicly accessible project file using an outdated cipher algorithm. An attacker may use this to brute force the credentials and take over the system. |
Risk And Classification
Problem Types: CWE-538
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Siemens | Simatic Pcs 7 | 9.0 | - | All | All |
| Application | Siemens | Simatic Pcs 7 | 9.1 | - | All | All |
| Application | Siemens | Simatic Pcs 7 | All | All | All | All |
| Application | Siemens | Simatic Wincc | All | All | All | All |
| Application | Siemens | Simatic Wincc | 13 | - | All | All |
| Application | Siemens | Simatic Wincc | 13 | sp1 | All | All |
| Application | Siemens | Simatic Wincc | 13 | sp2 | All | All |
| Application | Siemens | Simatic Wincc | 14.0.1 | All | All | All |
| Application | Siemens | Simatic Wincc | 15 | All | All | All |
| Application | Siemens | Simatic Wincc | 15.1 | - | All | All |
| Application | Siemens | Simatic Wincc | 15.1 | update_1 | All | All |
| Application | Siemens | Simatic Wincc | 15.1 | update_2 | All | All |
| Application | Siemens | Simatic Wincc | 15.1 | update_3 | All | All |
| Application | Siemens | Simatic Wincc | 15.1 | update_4 | All | All |
| Application | Siemens | Simatic Wincc | 15.1 | update_5 | All | All |
| Application | Siemens | Simatic Wincc | 15.1 | update_6 | All | All |
| Application | Siemens | Simatic Wincc | 16 | - | All | All |
| Application | Siemens | Simatic Wincc | 16 | update1 | All | All |
| Application | Siemens | Simatic Wincc | 16 | update2 | All | All |
| Application | Siemens | Simatic Wincc | 16 | update3 | All | All |
| Application | Siemens | Simatic Wincc | 16 | update4 | All | All |
| Application | Siemens | Simatic Wincc | 17 | - | All | All |
| Application | Siemens | Simatic Wincc | 17 | update1 | All | All |
| Application | Siemens | Simatic Wincc | 17 | update2 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | - | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update1 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update10 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update11 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update12 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update13 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update14 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update15 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update16 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update17 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update18 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update2 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update3 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update4 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update5 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update6 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update7 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update8 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update9 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | update_1 | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | - | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | sp1 | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | sp1_update1 | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | sp1_update2 | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | sp2 | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | sp2_update1 | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | sp2_update2 | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | sp2_update3 | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | sp2_update4 | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | sp2_update5 | All | All |
| Application | Siemens | Simatic Wincc | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cert-portal.siemens.com/productcert/pdf/ssa-914168.pdf | MISC | cert-portal.siemens.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590748 Siemens SIMATIC WinCC and PCS Multiple Vulnerabilities (ICSA-22-041-02)