QID 591164

Date Published: 2022-11-07

QID 591164: Siemens SIMATIC NET PC Software Unquoted Search Path Vulnerability (SSA-312271)

AFFECTED PRODUCTS
The following Siemens products are affected:
SIMATIC NET PC Software V14: All versions prior to V14 SP1 Update 14
SIMATIC NET PC Software V15: All versions
SIMATIC NET PC Software: V16 All versions prior to V16 Update 3

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"

Successful exploitation of this vulnerability allows authorized local users with administrative privileges to execute custom code with SYSTEM-level privileges.

  • CVSS V3 rated as High - 6.7 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SSA-312271 for affected packages and patching details.

    CVEs related to QID 591164

    Software Advisories
    Advisory ID Software Component Link
    SSA-312271 URL Logo cert-portal.siemens.com/productcert/html/ssa-312271.html