Missing Authentication for Critical Function in Siemens products - CVE-2021-27395
Published: October 13, 2021
Vulnerability identifier: #VU57343
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2021-27395
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Siemens
Affected software:
SIMATIC Process Historian 2013
SIMATIC Process Historian 2019
SIMATIC Process Historian 2020
SIMATIC Process Historian 2014
SIMATIC Process Historian 2013
SIMATIC Process Historian 2019
SIMATIC Process Historian 2020
SIMATIC Process Historian 2014
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the software that is used for critical functionalities lacks authentication. A remote attacker can maliciously insert, modify or delete data.
How to mitigate CVE-2021-27395
Install updates from vendor's website.