CVE-2015-1358 describes a vulnerability in Siemens SIMATIC WinCC (TIA Portal) and WinCC flexible where the remote-management module fails to properly encrypt credentials during transit. This allows remote attackers to intercept and decrypt cleartext credentials by sniffing network traffic. The vulnerability has a CVSS score of 5.0, indicating a medium severity, with a network attack vector, low attack complexity, and potential for confidentiality compromise. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite this, the CVE has garnered significant community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
13.0CPE matchmatch criteria | cpe:2.3:a:siemens:wincc:13.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.