← Vulnerability feed

Vulnerability record · CVE-2015-1355 · published 18 February 2015

CVE-2015-1355: Siemens simatic step 7 vulnerability

Siemens · Simatic Step 7

Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes it easier for local users to determine cleartext passwords by reading a project file and conducting a brute-force attack.

2.1 CVSS 2.0 Low EPSS 0.37% · top 71.5% CWE-310 · CWE-310
2.1CVSS 2.0 base score
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes it easier for local users to determine cleartext passwords by reading a project file and conducting a brute-force attack.

AV:L/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-1355 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-25910Siemens simatic pcs 7 code injection vulnerabilityA vulnerability has been identified in SIMATIC PCS 7 (All versions < V9.1 SP2 UC04), SIMATIC S7-PM (All versions < V5.7 SP1 HF1), SIMATIC S7-PM (All …EPSS 1.0%8.2CVE-2020-7587Siemens opcenter execution discrete uncontrolled resource consumption vulnerabilityA vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcent…EPSS 2.5%7.8CVE-2021-42029Siemens simatic step 7 improper access control vulnerabilityA vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5),…EPSS 0.24%7.8CVE-2020-7585Siemens simatic pcs 7 uncontrolled search path element vulnerabilityA vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All …EPSS 0.45%7.8CVE-2020-7586Siemens simatic pcs 7 heap-based buffer overflow vulnerabilityA vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All …EPSS 0.42%6.9CVE-2015-1594Siemens starter vulnerabilityUntrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0 SP4 Upd9 and 8.1 before Upd1; SIMATIC STEP 7 bef…EPSS 0.40%6.9CVE-2012-3015Siemens simatic pcs7 vulnerabilityUntrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7 7.1 SP3 and earlier and other products, allows l…EPSS 0.46%6.8CVE-2015-1601Siemens simatic step 7 vulnerabilitySiemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 allows man-in-the-middle attackers to obtain sensitive information or modify transmi…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2015-1355), CISA KEV, FIRST EPSS (scores of 2026-09-30). This page is refreshed as NVD updates the record.