QID 590748

Date Published: 2022-03-21

QID 590748: Siemens SIMATIC WinCC and PCS Multiple Vulnerabilities (ICSA-22-041-02)

AFFECTED PRODUCTS
Siemens reports these vulnerabilities affect the following SIMATIC products:
SIMATIC WinCC v15 and earlier: All versions
SIMATIC WinCC v16: All versions prior to v16 Update 5
SIMATIC WinCC v17: All versions prior to v17 Update 2
SIMATIC WinCC v17: All versions since and including v17 Update 2

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"

Successful exploitation of these vulnerabilities may allow attackers to retrieve and brute force password hashes and access other systems.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-22-041-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590748

    Software Advisories
    Advisory ID Software Component Link
    ICSA-22-041-02 URL Logo www.us-cert.gov/ics/advisories/ICSA-22-041-02