QID 591128
Date Published: 2022-10-20
QID 591128: Siemens SIMATIC STEP 7 TIA Portal Improper Access Control Vulnerability (SSA-350757)
SIMATIC STEP 7 (TIA Portal) is an engineering software to configure and program SIMATIC controllers and Standard PCs running WinAC RTX.
AFFECTED PRODUCTS
The following Siemens products are affected:
SIMATIC STEP 7 (TIA Portal) V15: All versions
SIMATIC STEP 7 (TIA Portal) V16:All versions prior to V16 Update 5
SIMATIC STEP 7 (TIA Portal) V17: All versions prior to V17 Update 2
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens.
A local user who is tricked into exploiting these vulnerabilities could possibly escalate privileges for an attacker.
Solution
Customers are advised to refer to CERT MITIGATIONS section SSA-350757 for affected packages and patching details.
Vendor References
CVEs related to QID 591128
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SSA-350757 |
|