QID 590592
Date Published: 2021-12-02
QID 590592: Siemens SIMATIC, SINAMICS, SINEC, SINEMA, SINUMERIK (Update I) Unquoted Search Path or Element Vulnerability (ICSA-20-161-04)
AFFECTED PRODUCTS
The following Siemens products are affected:
SIMATIC Automation Tool: All versions
SIMATIC NET PC software: All versions after v16 and prior to v16 Upd3
SIMATIC WinCC v7.4: All versions prior to v7.4 SP1 Update 14
SIMATIC WinCC v7.5: All versions prior to v7.5 SP1 Update 3
SINAMICS Startdrive: All versions
SINEMA Server: All versions prior to v14 SP3
SINEMA Server: All versions
SIMATIC Automation Tool: All versions prior to v4 SP2
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"
Successful exploitation of this vulnerability could allow authorized local users with administrative privileges to execute custom code with SYSTEM level privileges.
Customers are advised to refer to CERT MITIGATIONS section ICSA-20-161-04 for affected packages and patching details.
- ICSA-20-161-04 -
www.us-cert.gov/ics/advisories/ICSA-20-161-04
CVEs related to QID 590592
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-20-161-04 |
|