Search by:
20 May 2019
Siemens has fixed vulnerabilities identified in SIMATIC WinCC and SIMATIC PCS 7. Both products are affected by multiple vulnerabilities, three of which were identified by Kaspersky Lab researchers.
One issue has to do with an RCE vulnerability, CVE-2019-10922, for which a CVSS v.3 base score of 9.8 has been calculated. The vulnerability enables an unauthenticated attacker with network access to affected installations to execute arbitrary code. It can be exploited on systems which are configured without “Encrypted Communication”. The exploitation of this vulnerability can affect the confidentiality, integrity, and availability of the information handled.
The issue is relevant both to new and old versions of affected products. To fix the vulnerability, the vendor recommends:
Three more vulnerabilities have also been identified in Siemens products:
These vulnerabilities affect the following solutions:
Siemens has released fixes for SIMATIC WinCC and SIMATIC PCS 7. The vendor is currently developing updates for the remaining solutions. According to the vendor’s recommendations, to mitigate the above issues users of affected products should only open project files from trusted locations and apply Defense-in-Depth.
Source: Siemens