SSA-282044 PUBLISHED CVSS 7.800000190734863 HIGH

The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
SiemensSIMATIC WinCC Visualization Architect (SiVArc) V19
SiemensModular PID CTRL Tool
SiemensSIMATIC S7-PLCSIM V17
SiemensSIMATIC WinCC V8.0
SiemensTotally Integrated Automation Portal (TIA Portal) V19
SiemensSIMATIC eaSie Workflow Skills
SiemensSIMATIC WinCC Unified PC Runtime V20
SiemensTeleControl Server Basic V3.1
SiemensSIMATIC S7-PLCSIM V19
SiemensSIMATIC WinCC Runtime Professional V20
SiemensSIMATIC eaSie PCS 7 Skill Package (6DL5424-0BX00-0AV8)
SiemensSIMATIC PCS 7 Advanced Process Library V9.1
SiemensTotally Integrated Automation Portal (TIA Portal) V18
SiemensSIMATIC MTP Integrator V2.x
SiemensSIMATIC PCS 7 V9.1
SiemensSIMATIC NET PC Software V18
SiemensTotally Integrated Automation Portal (TIA Portal) V20
SiemensSIMATIC PCS 7 Industry Library V9.0
SiemensSIMATIC PDM Maintenance Station V5.0
SiemensTIA Portal Test Suite V17

…and 119 more

Timeline

References

…and 16 more

Open in Interactive Console →