VDB

CVE-2019-10935

CVE-2019-10935 PUBLISHED CVSS 7.199999809265137 HIGH

A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd11), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP2 with WinCC V7.4 SP1 Upd11), SIMATIC WinCC Professional (TIA Portal V13) (All versions), SIMATIC WinCC Professional (TIA Portal V14) (All versions), SIMATIC WinCC Professional (TIA Portal V15) (All versions), SIMATIC WinCC Runtime Professional V13 (All versions), SIMATIC WinCC Runtime Professional V14 (All versions), SIMATIC WinCC Runtime Professional V15 (All versions), SIMATIC WinCC V7.2 and earlier (All versions), SIMATIC WinCC V7.3 (All versions), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Upd 11), SIMATIC WinCC V7.5 (All versions < V7.5 Upd 3). The SIMATIC WinCC DataMonitor web application of the affected products allows to upload arbitrary ASPX code. The security vulnerability could be exploited by an authenticated attacker with network access to the WinCC DataMonitor application. No user interaction is required to exploit this vulnerability. The vulnerability impacts confidentiality, integrity, and availability of the affected device. At the stage of publishing this security advisory no public exploitation is known.

EPSS 0.52% · 67.1th percentile

Risk Scores

CVSS 3.0
7.199999809265137
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.52%
67.1th percentile

Affected Products

VendorProductVersions
Siemens AGSIMATIC WinCC V7.4*
Siemens AGSIMATIC WinCC Runtime Professional V14All versions < V14.1 Upd 8
Siemens AGSIMATIC WinCC V7.2 and earlierAll versions
Siemens AGSIMATIC WinCC Runtime Professional V15All versions < V15.1 Upd 3
Siemens AGSIMATIC PCS 7 V8.1All versions < V8.1 with WinCC V7.3 Upd 19
Siemens AGSIMATIC PCS 7 V9.0All versions < V9.0 SP2 with WinCC V7.4 SP1 Upd11
Siemens AGSIMATIC WinCC V7.5All versions < V7.5 Upd 3
Siemens AGSIMATIC WinCC Runtime Professional V13All versions
siemenssimatic_wincc7.3, 7.3, 7.3
siemenssimatic_wincc_runtime14, 13, 13
siemenssimatic_pcs_79.0, 8.0, 8.2
Siemens AGSIMATIC PCS 7 V8.0 and earlierAll versions
Siemens AGSIMATIC WinCC V7.3All versions < V7.3 Upd 19
Siemens AGSIMATIC PCS 7 V8.2All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd 11
Siemens AGSIMATIC WinCC Professional (TIA Portal V14)All versions < V14 SP1 Upd 9
Siemens AGSIMATIC WinCC Professional (TIA Portal V13)*
Siemens AGSIMATIC WinCC Professional (TIA Portal V15)All versions < V15.1 Upd 3

Timeline

  • Jul 9, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›