PT-2019-2105 · Siemens · Simatic Wincc+1

Published

2019-05-14

·

Updated

2020-10-02

·

CVE-2019-10922

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SIMATIC PCS 7 versions 8.0 and earlier SIMATIC PCS 7 versions 8.1 and newer SIMATIC WinCC versions 7.2 and earlier SIMATIC WinCC versions 7.3 and newer
Description A security issue has been identified that allows an attacker with network access to execute arbitrary code on affected installations configured without "Encrypted Communication". This can be exploited by an unauthenticated attacker with no user interaction required, impacting the confidentiality, integrity, and availability of the device. At the time of publication, no public exploitation of this issue was known.
Recommendations For SIMATIC PCS 7 versions 8.0 and earlier, consider enabling "Encrypted Communication" to mitigate the risk. For SIMATIC PCS 7 versions 8.1 and newer, consider enabling "Encrypted Communication" to mitigate the risk. For SIMATIC WinCC versions 7.2 and earlier, consider enabling "Encrypted Communication" to mitigate the risk. For SIMATIC WinCC versions 7.3 and newer, consider enabling "Encrypted Communication" to mitigate the risk. As a temporary workaround, consider restricting network access to affected installations until a fix is available.

Fix

Missing Authentication

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01861
CVE-2019-10922

Affected Products

Simatic Pcs 7
Simatic Wincc