Lucene search

K
cveSiemensCVE-2021-44222
HistoryJul 12, 2022 - 10:15 a.m.

CVE-2021-44222

2022-07-1210:15:10
CWE-306
siemens
web.nvd.nist.gov
48
4
cve-2021-44222
simatic easie
core package
mqtt
authentication
remote attacker
arbitrary messages
nvd

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

62.0%

A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service of affected systems does not perform authentication in the default configuration. This could allow an unauthenticated remote attacker to send arbitrary messages to the service and thereby issue arbitrary requests in the affected system.

Affected configurations

Nvd
Node
siemenssimatic_easie_core_packageRange<22.00
VendorProductVersionCPE
siemenssimatic_easie_core_package*cpe:2.3:a:siemens:simatic_easie_core_package:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "SIMATIC eaSie Core Package",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions < V22.00"
      }
    ]
  }
]

Social References

More

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

62.0%

Related for CVE-2021-44222