← Vulnerability feed

Vulnerability record · CVE-2015-1594 · published 7 March 2015

CVE-2015-1594: Siemens starter vulnerability

Siemens · Starter

Untrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0 SP4 Upd9 and 8.1 before Upd1; SIMATIC STEP 7 before 5.5 SP1 HF2, 5.5 SP2 before HF7, 5.5 SP3, and 5.5 SP4 before HF4; SIMOTION Scout before 4.4; and STARTER before 4.4 HF3 allows local users to gain privileges via a Trojan horse application file.

6.9 CVSS 2.0 Medium EPSS 0.40% · top 67.7%
6.9CVSS 2.0 base score
0.40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Untrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0 SP4 Upd9 and 8.1 before Upd1; SIMATIC STEP 7 before 5.5 SP1 HF2, 5.5 SP2 before HF7, 5.5 SP3, and 5.5 SP4 before HF4; SIMOTION Scout before 4.4; and STARTER before 4.4 HF3 allows local users to gain privileges via a Trojan horse application file.

AV:L/AC:M/Au:N/C:C/I:C/A:C

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-1594 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-25910Siemens simatic pcs 7 code injection vulnerabilityA vulnerability has been identified in SIMATIC PCS 7 (All versions < V9.1 SP2 UC04), SIMATIC S7-PM (All versions < V5.7 SP1 HF1), SIMATIC S7-PM (All …EPSS 1.0%8.2CVE-2020-7587Siemens opcenter execution discrete uncontrolled resource consumption vulnerabilityA vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcent…EPSS 2.5%7.8CVE-2021-42029Siemens simatic step 7 improper access control vulnerabilityA vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5),…EPSS 0.24%7.8CVE-2020-7586Siemens simatic pcs 7 heap-based buffer overflow vulnerabilityA vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All …EPSS 0.42%7.8CVE-2020-7585Siemens simatic pcs 7 uncontrolled search path element vulnerabilityA vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All …EPSS 0.45%6.9CVE-2012-3015Siemens simatic pcs7 vulnerabilityUntrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7 7.1 SP3 and earlier and other products, allows l…EPSS 0.46%6.8CVE-2015-1601Siemens simatic step 7 vulnerabilitySiemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 allows man-in-the-middle attackers to obtain sensitive information or modify transmi…EPSS 1.4%6.7CVE-2020-7581Siemens opcenter execution discrete unquoted search path vulnerabilityA vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcent…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2015-1594), CISA KEV, FIRST EPSS (scores of 2026-09-30). This page is refreshed as NVD updates the record.