PatchSiren cyber security CVE debrief
CVE-2017-2684 Siemens CVE debrief
CVE-2017-2684 affects Siemens SIMATIC Logon prior to V1.5 SP3 Update 2. According to the vendor and NVD records, an attacker who already knows a valid user name and has physical or network access to the affected system could bypass application-level authentication. NVD rates the issue Critical with CVSS 3.0 vector AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H.
- Vendor
- Siemens
- Product
- Simatic Logon
- CVSS
- CRITICAL 9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-13
- Original CVE updated
- 2018-06-12
- Advisory published
- 2017-02-13
- Advisory updated
- 2018-06-12
Who should care
Industrial control system operators, Siemens SIMATIC Logon administrators, OT security teams, and any organization using affected SIMATIC Logon versions should review exposure. Systems where attackers may have local access, network reachability, or shared-user knowledge are especially relevant.
Technical summary
The weakness is an authentication bypass in Siemens SIMATIC Logon, with the vulnerable range described by Siemens as prior to V1.5 SP3 Update 2. The attacker needs knowledge of a valid user name and physical or network access to the target system. The NVD record shows a high-severity impact profile with changed scope and high confidentiality, integrity, and availability impact.
Defensive priority
High. The issue is remotely reachable in some deployments, has no user-interaction requirement, and can enable bypass of an application-level authentication boundary. Even though attack complexity is listed as high, the potential impact on an industrial environment justifies prompt review and remediation.
Recommended defensive actions
- Verify whether any deployed Siemens SIMATIC Logon installations are at or below the affected version range described by the vendor.
- Apply Siemens' fixed release: V1.5 SP3 Update 2 or later, if available in your environment.
- Restrict physical and network access to hosts running SIMATIC Logon, especially where the application is exposed beyond trusted administrative networks.
- Review account and username exposure controls so valid usernames are not unnecessarily discoverable.
- Monitor authentication and access logs for unexpected logon behavior or successful access that does not match normal user patterns.
- Use the Siemens security advisory and NVD record as the primary references for affected versions and remediation guidance.
Evidence notes
This debrief is based only on the supplied NVD record and the referenced Siemens advisory metadata. The CVE was published on 2017-02-22 and modified on 2026-05-13; those dates are used only as record timing context. The source describes the issue as an application-level authentication bypass in SIMATIC Logon prior to V1.5 SP3 Update 2, requiring knowledge of a valid user name and physical or network access. NVD lists CVSS 3.0 AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H and includes the Siemens vendor advisory reference.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-2684 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-2684
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-2684 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2684
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-931064.pdf
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.