A total of four vulnerabilities were patched in Simatic Step 7, which could allow a potential attacker to learn user passwords, gain privileges, or intercept industrial communication.

Simatic Step is a Siemens that allows the creation of control logic programs used in industrial production. It can also be used to program computers equipped with WinAC RTX.
One of the vulnerabilities, identified as CVE-2015-1355, refers to poor protection of user passwords on the device, due to the use of a weak hashing algorithm.
According to the company's security bulletin, an attacker with read access to the project file could reconstruct the user's log-in passwords.
The same bulletin reports that another vulnerability, designated CVE-2015-1356, allows users to modify the permissions they have on the project's TIA (totally integrated automation) files. Siemens says that in order for the privileges to be active, a user needs to be prompted to download the file in question.
Both of these vulnerabilities have a low severity rating according to the Common Vulnerability Scoring System (CVSS), 2.1 and 2.6, respectively.
However, in a bulletin published on Tuesday, Siemens reported a more serious vulnerability (CVE-2015-1601), which could allow for control and alteration of communication on TCP port 102.
An attacker with access to the network path could resort to man-in-the-middle to mediate between the client and the server to achieve their goal. The CVSS score for this vulnerability is 5.8.
The fourth vulnerability (CVE-2015-1602) patched by Siemens is again related to TIA files and passwords. By exploiting the vulnerability, an attacker would be able to discover “security codes or passwords on the web server,” the company says.
None of the vulnerabilities patched by Siemens with the release of Update 1 for Simatic Step 7 SP1 V13 can be exploited remotely, and the malicious user would need to already have local access to the TIA project files or the network path between the client and the server.
The general recommendation is to implement a security policy for network access through segmentation (firewalls, DMZs, VPN), implement physical security, and ensure system integrity by implementing security mechanisms for secure access to network systems.
