Headline
CVE-2021-42029
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC STEP 7 (TIA Portal) V17 (All versions < V17 Update 2). An attacker could achieve privilege escalation on the web server of certain devices due to improper access control vulnerability in the engineering system software. The attacker needs to have direct access to the impacted web server.
%PDF-1.5 %���� 1 0 obj << /D [2 0 R /XYZ 70.866 771.024 null] >> endobj 3 0 obj << /D [2 0 R /XYZ 70.866 613.09 null] >> endobj 4 0 obj << /D [2 0 R /XYZ 70.866 519.127 null] >> endobj 5 0 obj << /D [2 0 R /XYZ 70.866 260.371 null] >> endobj 6 0 obj << /D [7 0 R /XYZ 70.866 693.211 null] >> endobj 8 0 obj << /D [7 0 R /XYZ 85.039 272.859 null] >> endobj 9 0 obj << /D [10 0 R /XYZ 70.866 740.294 null] >> endobj 11 0 obj << /S /GoTo /D [2 0 R /Fit] >> endobj 2 0 obj << /Contents 12 0 R /Type /Page /Resources 13 0 R /Parent 14 0 R /Annots [15 0 R 16 0 R 17 0 R 18 0 R 19 0 R 20 0 R 21 0 R 22 0 R] /MediaBox [0 0 595.276 841.89] >> endobj 15 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [458.38 419.565 518.276 429.089] >> endobj 17 0 obj << /A << /S /URI /Type /Action /URI (https://support.industry.siemens.com/cs/gb/en/view/109775861/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 375.512 518.276 387.049] >> endobj 19 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [302.649 338.277 433.497 350.954] >> endobj 20 0 obj << /A << /S /URI /Type /Action /URI (https://support.industry.siemens.com/cs/gb/en/view/109784441/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 309.562 518.276 321.098] >> endobj 22 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [302.649 272.326 433.497 285.004] >> endobj 13 0 obj << /ProcSet [/PDF /Text] /Font << /F54 23 0 R /F51 24 0 R >> >> endobj 12 0 obj << /Filter /FlateDecode /Length 3489 >> stream xڽ[Ks�8��W�6TU/L���d�<��ז�ښ́�h�;��#����e��%z��C"ݍ~7���ד�G’g�h>HY��d0����$�4e���h2�=�)�Y^������&o��S��b���O��9e���C�}n,�Z�’�������G�?F��������x���H>�N~�#L���A�dj����@iɴ�x�nN�q���L"���V�iK�ڂ��Q.Y���3H��’60���T��h�z� �5��朳$5��k ��Ii��H@�އ?���6 ��-�tb�E�ܥ@,�M�� �IB�R��J�{���Y��$����jՁ�L��(�-����yc��]�˵?��.8y�ˏ�@*�R�K��dR’�(�*a\�$��0��ʹ̗��bJ�a�%,3�:�%5��+�`֤��Ptޤ�(;W� {�(��:!X�W�V��?�<�@�HNo�U]��E�h�la�bna �ǯ� r��_g�N��7�s�?ct�R�qw7�q���Ey�a�e�9px�I�u�%I�|���^`i�6i�1�\�q�)��G,���!4����Ir?u�r��u�����\HxT���;K����⻀ި89 �T�Ϊ> �a�٫zL��cqu��1��iq���9l�����l��y(u��@�M��Q�q/�b���ui0E����?�ѷ�XKq�{��((!�{���轡����_b_�c�W��� l/����g�4L�����(��q�O�u>y�����}���4�>��"�������P#�7�߾P��4�kٲ����Y)��w��?�#PGx�<�a=|���u�;}��)l�`nICt�%��irXu�o.����t��F�c�P�$�ur�"=����*�D�Y�lYd�z���L�U�8El�4\NIA}��qE�i1��ż��7����Si����i��&| �J�˸���گ�]L�*m8jU%��2/��OC�0q���X� <�’���u�nn��o�q��s��CEd<_&�Q�ԓ6(��X�=��Á"f�6�٠�[� "u�����P��?i����>"���4��d4�p�X���z����O:�i4:�o�<�4��ENU�@���"Ԏ���>��q6����a�w��/��W�U�m1u~��őH�(��[1�W��8��e>�#_�������������,KSլMiʉ*v܌�^�S5��:�H٘/w�)�Q.�q�fM6A�s?P��%�?�{5�|�}t��d���x��P�h�gl�7Z4���Jpk����L����� G�h��+O�d>����t�M���D��"`0/��T�L����’O�Ty�%���ڽ���鑵����.ܽx��]6�B���A]�8D;� �p���Y���d9�<� ^�2�C~�=䁛�I82�5���T0���(m����ET�?�q�+|��ԧ�x�q�[��9���||�=t5ذ���h<��I��$�~��?@� ��q�m�"g⩩1כ�Ր’ ��5�m���� i�w��r�mM4[��a��0�۠o8�e�ه��-��W�������u[r��� �.�y���i�=UN������ �)��M��aݩ�"+�~��/o/Fo�t�;ȷb�gg�*�]�$���P,��>� �_]�>����t�3$���H�3������f/ ��:�o��1�1�SED����j��Z��nG�?t�,�.1P��S� �4i�e�����K�����!#��!WT ����~��n4��yZ߆�eւW�����v�x\�����v��;.ꈹ�?٫�8�IojX��x��+S)�8i�r~��#��+���5����a��RjT?��]�S�k�%�G� э���(l�TCyy�`Q�FT�����>�hF��Wd ���w1c�9�x|�pNaqD�L{ΧӐ��}}=�����V��L ��4t��yňX��?�/��fe��A��gƛ��i��K�c��w���ZQK!H�Glt���1IR-��-��?�%�ɪmlQ�-���p���uq���[-z6�w5�q� Z$%b/#�S�(geh�L�ٗע��Z���"7�-�z-�?�Ê�l����:��^$��<䦔>,w�}Jcj��c!K!}{X���gg��b�� �dE9٬�.IB4�ڈ�B��UĠ�g����׳�