CVE-2017-6868 is an improper authentication vulnerability affecting Siemens SIMATIC CP 44x-1 RNA modules, versions prior to 1.4.1. An unauthenticated remote attacker can exploit this flaw via Port 102/TCP to perform administrative actions on the Communication Process (CP), provided the configuration file is stored on the RNA's CPU. This vulnerability carries a high CVSS score of 8.1, indicating a severe impact with high confidentiality, integrity, and availability compromise, though it has high attack complexity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, with limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4.0CPE matchmatch criteria | cpe:2.3:a:siemens:simatic_cp_44x-1_redundant_network_access_modules:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.