QID 591050

Date Published: 2022-09-15

QID 591050: Siemens SIMATIC WinCC Vulnerability (SSA-363107) (icsa-22-132-06)

AFFECTED PRODUCTS
SIMATIC WinCC V7.4 and earlier:All versions
SIMATIC WinCC V7.5:All versions prior to V7.5 SP2 Update 8

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

A vulnerability was found in SIMATIC WinCC that could allow authenticated attackers to escape the Kiosk Mode.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution

    Customers are advised to refer to Schneider Electric MITIGATIONS section SSA-363107 for affected packages and patching details.

    CVEs related to QID 591050

    Software Advisories
    Advisory ID Software Component Link
    icsa-22-132-06 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-132-06
    ssa-363107 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-363107.pdf