CVE-2015-1602 describes a vulnerability in Siemens SIMATIC STEP 7 (TIA Portal) versions 12 and 13 before 13 SP1 Upd1, where project files improperly store password data. This flaw allows local attackers to easily retrieve cleartext protection-level or web-server passwords by reading these files. The vulnerability has a low severity CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), indicating local access and low attack complexity are required for potential disclosure of confidential information. There is no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage beyond an initial SecurityWeek article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 13.0CPE matchmatch criteria | cpe:2.3:a:siemens:simatic_step_7:*:sp1:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:a:siemens:simatic_step_7:12.0:*:*:*:*:*:*:* | ||
13.0CPE matchmatch criteria | cpe:2.3:a:siemens:simatic_step_7:13.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.