Siemens SIMATIC Products ICSA-19-134-08 Multiple Security Vulnerabilities
BID:108404
Info
Siemens SIMATIC Products ICSA-19-134-08 Multiple Security Vulnerabilities
| Bugtraq ID: | 108404 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-10918 CVE-2019-10917 CVE-2019-10916 |
| Remote: | Yes |
| Local: | Yes |
| Published: | May 14 2019 12:00AM |
| Updated: | May 22 2019 06:00AM |
| Credit: | Vladimir Dashchenko and Sergey Temnikov from Kaspersky Lab, CNCERT/CC, and ChengBin Wang from Guoli Security Technology |
| Vulnerable: |
Siemens SIMATIC WinCC Runtime Professional 0 Siemens SIMATIC WinCC (TIA Portal) v15 Siemens SIMATIC WinCC (TIA Portal) V14 Siemens SIMATIC WinCC (TIA Portal) V13 Siemens SIMATIC WinCC 7.5 Siemens SIMATIC WinCC 7.4 Siemens SIMATIC WinCC 7.3 Siemens SIMATIC WinCC 7.2 Siemens SIMATIC WinCC 7.0 Siemens SIMATIC WinCC 6.2 Siemens SIMATIC PCS 7 9.0 Siemens SIMATIC PCS 7 8.2 Siemens SIMATIC PCS 7 8.1 Siemens SIMATIC PCS 7 8.0 Siemens SIMATIC PCS 7 7 |
| Not Vulnerable: |
Siemens SIMATIC WinCC 7.5 Update 3 |
Discussion
Siemens SIMATIC Products ICSA-19-134-08 Multiple Security Vulnerabilities
Siemens SIMATIC products are prone to following security vulnerabilities:
1. A denial-of-service vulnerability
2. An SQL injection vulnerability3.
3. An arbitrary command execution
Exploiting these vulnerabilities could allow an attacker to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, bypass security restrictions, or execute arbitrary code or cause a denial of service condition.
The following Siemens SIMATIC products are affected:
SIMATIC PCS 7 version 8.0 and prior
SIMATIC PCS 7 version 8.1
SIMATIC PCS 7 version 8.2
SIMATIC PCS 7 version 9.0
SIMATIC WinCC (TIA Portal) version 13
SIMATIC WinCC (TIA Portal) version 14
SIMATIC WinCC (TIA Portal) version 15
SIMATIC WinCC Runtime Professional, all version
SIMATIC WinCC version 7.2 and prior
SIMATIC WinCC version 7.3
SIMATIC WinCC version 7.4
SIMATIC WinCC version 7.5, all version prior to version 7.5 Update 3
Siemens SIMATIC products are prone to following security vulnerabilities:
1. A denial-of-service vulnerability
2. An SQL injection vulnerability3.
3. An arbitrary command execution
Exploiting these vulnerabilities could allow an attacker to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, bypass security restrictions, or execute arbitrary code or cause a denial of service condition.
The following Siemens SIMATIC products are affected:
SIMATIC PCS 7 version 8.0 and prior
SIMATIC PCS 7 version 8.1
SIMATIC PCS 7 version 8.2
SIMATIC PCS 7 version 9.0
SIMATIC WinCC (TIA Portal) version 13
SIMATIC WinCC (TIA Portal) version 14
SIMATIC WinCC (TIA Portal) version 15
SIMATIC WinCC Runtime Professional, all version
SIMATIC WinCC version 7.2 and prior
SIMATIC WinCC version 7.3
SIMATIC WinCC version 7.4
SIMATIC WinCC version 7.5, all version prior to version 7.5 Update 3
Exploit / POC
Siemens SIMATIC Products ICSA-19-134-08 Multiple Security Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Siemens SIMATIC Products ICSA-19-134-08 Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Siemens SIMATIC Products ICSA-19-134-08 Multiple Security Vulnerabilities
References:
References:
- Siemens Homepage (Siemens)
- Advisory (ICSA-19-134-08) Siemens SIMATIC PCS 7, WinCC, TIA Portal (ICS CERT)