PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-2684 Siemens CVE debrief

CVE-2017-2684 affects Siemens SIMATIC Logon prior to V1.5 SP3 Update 2. According to the vendor and NVD records, an attacker who already knows a valid user name and has physical or network access to the affected system could bypass application-level authentication. NVD rates the issue Critical with CVSS 3.0 vector AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H.

Vendor
Siemens
Product
Simatic Logon
CVSS
CRITICAL 9
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-13
Original CVE updated
2018-06-12
Advisory published
2017-02-13
Advisory updated
2018-06-12

Who should care

Industrial control system operators, Siemens SIMATIC Logon administrators, OT security teams, and any organization using affected SIMATIC Logon versions should review exposure. Systems where attackers may have local access, network reachability, or shared-user knowledge are especially relevant.

Technical summary

The weakness is an authentication bypass in Siemens SIMATIC Logon, with the vulnerable range described by Siemens as prior to V1.5 SP3 Update 2. The attacker needs knowledge of a valid user name and physical or network access to the target system. The NVD record shows a high-severity impact profile with changed scope and high confidentiality, integrity, and availability impact.

Defensive priority

High. The issue is remotely reachable in some deployments, has no user-interaction requirement, and can enable bypass of an application-level authentication boundary. Even though attack complexity is listed as high, the potential impact on an industrial environment justifies prompt review and remediation.

Recommended defensive actions

  • Verify whether any deployed Siemens SIMATIC Logon installations are at or below the affected version range described by the vendor.
  • Apply Siemens' fixed release: V1.5 SP3 Update 2 or later, if available in your environment.
  • Restrict physical and network access to hosts running SIMATIC Logon, especially where the application is exposed beyond trusted administrative networks.
  • Review account and username exposure controls so valid usernames are not unnecessarily discoverable.
  • Monitor authentication and access logs for unexpected logon behavior or successful access that does not match normal user patterns.
  • Use the Siemens security advisory and NVD record as the primary references for affected versions and remediation guidance.

Evidence notes

This debrief is based only on the supplied NVD record and the referenced Siemens advisory metadata. The CVE was published on 2017-02-22 and modified on 2026-05-13; those dates are used only as record timing context. The source describes the issue as an application-level authentication bypass in SIMATIC Logon prior to V1.5 SP3 Update 2, requiring knowledge of a valid user name and physical or network access. NVD lists CVSS 3.0 AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H and includes the Siemens vendor advisory reference.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-2684 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-2684

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-2684 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2684

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.