QID 591174
Date Published: 2022-11-24
QID 591174: Siemens SIMATIC PCS 7, Step 7, Starter Incorrect Permission Assignment Vulnerability (SSA-661034)
AFFECTED PRODUCTS
The following Siemens products are affected:
SIMATIC PCS 7 V8.2 and earlier All versions
SIMATIC STEP 7 V5.X All versions prior to V5.7
SINAMICS STARTER (containing STEP 7 OEM version) All versions prior to V5.4 SP2 HF1
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"
Successful exploitation of this vulnerability could allow an attacker to change the content of certain metafiles and subsequently manipulate the parameters or behavior of devices configured by the affected software products.
Customers are advised to refer to CERT MITIGATIONS section SSA-661034 for affected packages and patching details.Workaround:
The vendor has advised restricting access to the engineering station to trusted users only.
CVEs related to QID 591174
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SSA-661034 |
|