← Vulnerability feed

Vulnerability record · CVE-2022-46141 · published 12 December 2023

CVE-2022-46141: Siemens simatic step 7 cleartext storage of sensitive data vulnerability

Siemens · Simatic Step 7

A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All versions < V19). An information disclosure vulnerability could allow a local attacker to gain access to the access level password of the SIMATIC S7-1200 and S7-1500 CPUs, when entered by a legitimate user in the hardware configuration of the affected application.

5.5 CVSS 3.1 Medium EPSS 0.14% · top 97.1% CWE-316 · CWE-316CWE-312 · Cleartext storage of sensitive data
5.5CVSS 3.1 base score
0.14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All versions < V19). An information disclosure vulnerability could allow a local attacker to gain access to the access level password of the SIMATIC S7-1200 and S7-1500 CPUs, when entered by a legitimate user in the hardware configuration of the affected application.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-46141 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-25910Siemens simatic pcs 7 code injection vulnerabilityA vulnerability has been identified in SIMATIC PCS 7 (All versions < V9.1 SP2 UC04), SIMATIC S7-PM (All versions < V5.7 SP1 HF1), SIMATIC S7-PM (All …EPSS 1.0%8.2CVE-2020-7587Siemens opcenter execution discrete uncontrolled resource consumption vulnerabilityA vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcent…EPSS 2.5%7.8CVE-2021-42029Siemens simatic step 7 improper access control vulnerabilityA vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5),…EPSS 0.24%7.8CVE-2020-7585Siemens simatic pcs 7 uncontrolled search path element vulnerabilityA vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All …EPSS 0.45%7.8CVE-2020-7586Siemens simatic pcs 7 heap-based buffer overflow vulnerabilityA vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All …EPSS 0.42%6.9CVE-2015-1594Siemens starter vulnerabilityUntrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0 SP4 Upd9 and 8.1 before Upd1; SIMATIC STEP 7 bef…EPSS 0.40%6.9CVE-2012-3015Siemens simatic pcs7 vulnerabilityUntrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7 7.1 SP3 and earlier and other products, allows l…EPSS 0.46%6.8CVE-2015-1601Siemens simatic step 7 vulnerabilitySiemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 allows man-in-the-middle attackers to obtain sensitive information or modify transmi…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2022-46141), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.