#VU65286 Missing Authentication for Critical Function in SIMATIC eaSie Core Package - CVE-2021-44222
Published: July 13, 2022 / Updated: July 14, 2022
SIMATIC eaSie Core Package
Siemens
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the underlying MQTT service does not perform authentication in the default configuration. A remote attacker can send arbitrary messages to the service and thereby issue arbitrary requests in the affected system.