A vulnerability has been identified in SIMATIC PCS 7 V9.0 and earlier (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1 UC01), SIMATIC WinCC Runtime Professional V16 and earlier (All versions), SIMATIC WinCC Runtime Professional V17 (All versions < V17 Upd4), SIMATIC WinCC V7.4 and earlier (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 8). An authenticated attacker could escape the WinCC Kiosk Mode by opening the printer dialog in the affected application in case no printer is installed.
References
Link | Resource |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-363107.pdf | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-05-20 06:15
Updated : 2022-06-14 03:15
NVD link : CVE-2022-24287
Mitre link : CVE-2022-24287
JSON object : View
CWE
CWE-1188
Insecure Default Initialization of Resource
Products Affected
siemens
- simatic_pcs_7
- simatic_wincc_runtime_professional
- simatic_wincc