CVE-2015-1355 describes a weak password-hash algorithm in Siemens SIMATIC STEP 7 (TIA Portal) prior to version 13 SP1. This vulnerability allows local attackers to easily recover cleartext passwords from project files using brute-force techniques. The CVSS score of 2.1 indicates low severity, with a local attack vector, low complexity, and potential for confidentiality impact. There is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB, and community discussion and media coverage have been minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 13.0CPE matchmatch criteria | cpe:2.3:a:siemens:simatic_step_7:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.