Vulnerabilities > CVE-2017-2684 - Unspecified vulnerability in Siemens Simatic Logon 1.5

047910
CVSS 9.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
high complexity
siemens
critical

Summary

Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the affected system, to bypass the application-level authentication.

Vulnerable Configurations

Part Description Count
Application
Siemens
1