CVE-2026-24349
WinCC Certificate Manager insufficiently protects key material that could allow an attacker to extract sensitive information. Siemens has released a new version for SIMATIC WinCC Unified PC Runtime V21 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens WinCC Certificate Manager are affected: SIMATIC WinCC Unified PC Runtime V16 vers:all/* SIMATIC WinCC Unified PC Runtime V17 vers:all/* SIMATIC WinCC Unified PC Runtime V18 vers:all/* SIMATIC WinCC Unified PC Runtime V19 vers:all/* SIMATIC WinCC Unified PC Runtime V20 vers:all/* SIMATIC WinCC Unified PC Runtime V21 vers:intdot/ CVSS Vendor Equipment Vulnerabilities v3 7.1 Siemens Siemens WinCC Certificate Manager Cleartext Storage in a File or on Disk Background Critical Infrastructure Sectors: Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany
EPSS 0.06% · 0.0th percentile
Risk Scores
Timeline
- Jun 9, 2026 CVE Published
- Jun 9, 2026 CVE Updated
- Jun 10, 2026 Coalition ESS Score
- Jun 23, 2026 EPSS Score
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-01 advisory
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-174-01.json advisory
- https://www.cve.org/CVERecord?id=CVE-2026-24349 technical
- https://support.industry.siemens.com/cs/ww/en/view/109991140/ vendor
- https://cwe.mitre.org/data/definitions/313.html technical
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N technical