Siemens SIMATIC SCADA and PCS 7 Systems

As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens’ ProductCERT Security Advisories (CERT Services | Services | Siemens Global). 

View CSAF

1. EXECUTIVE SUMMARY

  • CVSS v4 9.4
  • ATTENTION: Exploitable remotely/low attack complexity
  • Vendor: Siemens
  • Equipment: SIMATIC SCADA and PCS 7 Systems
  • Vulnerability: Execution with Unnecessary Privileges

2. RISK EVALUATION

Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code with high privileges.

3. TECHNICAL DETAILS

3.1 AFFECTED PRODUCTS

The following Siemens products are affected:

  • SIMATIC BATCH V9.1: All versions
  • SIMATIC Information Server 2020: All versions
  • SIMATIC Information Server 2022: All versions
  • SIMATIC PCS 7 V9.1: All versions
  • SIMATIC Process Historian 2020: All versions
  • SIMATIC Process Historian 2022: All versions
  • SIMATIC WinCC Runtime Professional V18: All versions
  • SIMATIC WinCC Runtime Professional V19: All versions
  • SIMATIC WinCC V7.4: All versions
  • SIMATIC WinCC V7.5: All versions prior to V7.5 SP2 Update 18
  • SIMATIC WinCC V8.0: All versions prior to V8.0 Update 5

3.2 Vulnerability Overview

3.2.1 EXECUTION WITH UNNECESSARY PRIVILEGES CWE-250

The affected products run their DB server with elevated privileges which could allow an authenticated attacker to execute arbitrary OS commands with administrative privileges.

This article has been indexed from All CISA Advisories

Read the original article:

Siemens SIMATIC SCADA and PCS 7 Systems