CVE-2022-24287
Published on: Not Yet Published
Last Modified on: 06/14/2022 10:15:00 AM UTC
Certain versions of Simatic Pcs 7 from Siemens contain the following vulnerability:
A vulnerability has been identified in SIMATIC PCS 7 V9.0 and earlier (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1 UC01), SIMATIC WinCC Runtime Professional V16 and earlier (All versions), SIMATIC WinCC Runtime Professional V17 (All versions < V17 Upd4), SIMATIC WinCC V7.4 and earlier (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 8). An authenticated attacker could escape the WinCC Kiosk Mode by opening the printer dialog in the affected application in case no printer is installed.
- CVE-2022-24287 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 4.6 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
cert-portal.siemens.com application/pdf |
![]() |
Related QID Numbers
- 591050 Siemens SIMATIC WinCC Vulnerability (SSA-363107) (icsa-22-132-06)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Siemens | Simatic Pcs 7 | 9.1 | All | All | All |
Application | Siemens | Simatic Pcs 7 | All | All | All | All |
Application | Siemens | Simatic Wincc | 7.5 | - | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp1 | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp1_update1 | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp1_update2 | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp2 | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp2_update1 | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp2_update2 | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp2_update3 | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp2_update4 | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp2_update5 | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp2_update6 | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp2_update7 | All | All |
Application | Siemens | Simatic Wincc | All | All | All | All |
Application | Siemens | Simatic Wincc Runtime Professional | 17 | All | All | All |
Application | Siemens | Simatic Wincc Runtime Professional | All | All | All | All |
- cpe:2.3:a:siemens:simatic_pcs_7:9.1:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_pcs_7:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:-:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp1_update1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp1_update2:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp2:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp2_update1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp2_update2:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp2_update3:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp2_update4:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp2_update5:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp2_update6:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp2_update7:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc_runtime_professional:17:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc_runtime_professional:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-24287 : A vulnerability has been identified in SIMATIC PCS 7 V9.0 and earlier All versions , SIMATIC PCS… twitter.com/i/web/status/1… | 2022-05-20 13:20:13 |