CVE-2019-10935 PUBLISHED CVSS 7.199999809265137 HIGH

A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd11), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP2 with WinCC V7.4 SP1 Upd11), SIMATIC WinCC Professional (TIA Portal V13) (All versions), SIMATIC WinCC Professional (TIA Portal V14) (All versions), SIMATIC WinCC Professional (TIA Portal V15) (All versions), SIMATIC WinCC Runtime Professional V13 (All versions), SIMATIC WinCC Runtime Professional V14 (All versions), SIMATIC WinCC Runtime Professional V15 (All versions), SIMATIC WinCC V7.2 and earlier (All versions), SIMATIC WinCC V7.3 (All versions), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Upd 11), SIMATIC WinCC V7.5 (All versions < V7.5 Upd 3). The SIMATIC WinCC DataMonitor web application of the affected products allows to upload arbitrary ASPX code. The security vulnerability could be exploited by an authenticated attacker with network access to the WinCC DataMonitor application. No user interaction is required to exploit this vulnerability. The vulnerability impacts confidentiality, integrity, and availability of the affected device. At the stage of publishing this security advisory no public exploitation is known.

EPSS 0.52% · 66.5th percentile

Risk Scores

CVSS v3.0
7.199999809265137
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.52%
66.5th percentile

Affected Products

VendorProductVersions
Siemens AGSIMATIC WinCC V7.4All versions < V7.4 SP1 Upd 11
Siemens AGSIMATIC WinCC Runtime Professional V14All versions < V14.1 Upd 8
Siemens AGSIMATIC WinCC V7.2 and earlierAll versions
Siemens AGSIMATIC WinCC Runtime Professional V15All versions < V15.1 Upd 3
Siemens AGSIMATIC PCS 7 V8.1All versions < V8.1 with WinCC V7.3 Upd 19
Siemens AGSIMATIC PCS 7 V9.0All versions < V9.0 SP2 with WinCC V7.4 SP1 Upd11
Siemens AGSIMATIC WinCC V7.5All versions < V7.5 Upd 3
Siemens AGSIMATIC WinCC Runtime Professional V13All versions
siemenssimatic_wincc7.4, 7.4, 0
siemenssimatic_wincc_runtime15.1, 13, 13
siemenssimatic_pcs_79.0, 8.2, 8.1
Siemens AGSIMATIC PCS 7 V8.0 and earlierAll versions
Siemens AGSIMATIC WinCC V7.3All versions < V7.3 Upd 19
Siemens AGSIMATIC PCS 7 V8.2All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd 11
Siemens AGSIMATIC WinCC Professional (TIA Portal V14)All versions < V14 SP1 Upd 9
Siemens AGSIMATIC WinCC Professional (TIA Portal V13)All versions
Siemens AGSIMATIC WinCC Professional (TIA Portal V15)All versions < V15.1 Upd 3

Timeline

References

Open in Interactive Console →