QID 590563
Date Published: 2021-11-15
QID 590563: Siemens SIMATIC WinCC Products (Update B) Multiple Vulnerabilities (ICSA-21-131-12)
AFFECTED PRODUCTS
The following Siemens SIMATIC WinCC products are affected:
SIMATIC WinCC Runtime Advanced v15: All versions prior to v15.1 SP1 Update 6
SIMATIC WinCC Runtime Advanced v16: All versions prior to v16 Update 4
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"
Successful exploitation of these vulnerabilities could allow remote code execution, information disclosure and denial-of-service attacks under certain conditions.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-21-131-12 for affected packages and patching details.
Vendor References
- ICSA-21-131-12 -
www.us-cert.gov/ics/advisories/ICSA-21-131-12
CVEs related to QID 590563
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-21-131-12 |
|