A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service of affected systems does not perform authentication in the default configuration. This could allow an unauthenticated remote attacker to send arbitrary messages to the service and thereby issue arbitrary requests in the affected system.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-08-04T04:17:24.864Z
Reserved: 2021-11-25T00:00:00
Link: CVE-2021-44222

No data.

Status : Modified
Published: 2022-07-12T10:15:10.050
Modified: 2024-11-21T06:30:36.823
Link: CVE-2021-44222

No data.