ICSA-24-102-08 PUBLISHED CVSS 7.800000190734863 HIGH

A vulnerability was identified in OPC Foundation Local Discovery Server which also affects Siemens products that could allow an attacker to escalate privileges under certain circumstances. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
SIMATIC NET PC Software V17
SIMATIC NET PC Software V15
SIMATIC WinCC
SIMATIC Process Historian 2022 OPC UA Server
SIMATIC WinCC Runtime Professional
SIMATIC Process Historian 2020 OPC UA Server
SIMATIC NET PC Software V18
TeleControl Server Basic V3
SIMATIC WinCC Unified PC Runtime V18
SIMATIC NET PC Software V14
OpenPCS 7 V9.1
SIMATIC NET PC Software V16

Timeline

References

Open in Interactive Console →