#VU57343 Missing Authentication for Critical Function in Siemens products - CVE-2021-27395
Published: October 13, 2021
Vulnerability identifier: #VU57343
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2021-27395
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
SIMATIC Process Historian 2013
SIMATIC Process Historian 2019
SIMATIC Process Historian 2020
SIMATIC Process Historian 2014
SIMATIC Process Historian 2013
SIMATIC Process Historian 2019
SIMATIC Process Historian 2020
SIMATIC Process Historian 2014
Software vendor:
Siemens
Siemens
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the software that is used for critical functionalities lacks authentication. A remote attacker can maliciously insert, modify or delete data.
Remediation
Install updates from vendor's website.