SSA-392859 PUBLISHED CVSS 7.300000190734863 HIGH

The affected devices do not properly sanitize user-controllable input when parsing user settings. This could allow an attacker to locally execute arbitrary commands in the host operating system with the privileges of the user.

Risk Scores

CVSS v3.1
7.300000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
SiemensSIMOCODE ES V19
SiemensTIA Portal Cloud V19
SiemensSIMOCODE ES V17
SiemensSIRIUS Safety ES V18 (TIA Portal)
SiemensSIRIUS Safety ES V19 (TIA Portal)
SiemensSIMATIC WinCC Unified V18
SiemensSIMATIC WinCC Unified PC Runtime V19
SiemensSIMATIC S7-PLCSIM V17
SiemensSIMATIC STEP 7 V19
SiemensSINAMICS Startdrive V17
SiemensSIMOTION SCOUT TIA V5.5
SiemensSIRIUS Soft Starter ES V18 (TIA Portal)
SiemensSIRIUS Soft Starter ES V17 (TIA Portal)
SiemensSIMATIC STEP 7 V18
SiemensSIMATIC WinCC V18
SiemensSIMATIC WinCC Unified PC Runtime V18
SiemensSIMATIC WinCC Unified V17
SiemensTIA Portal Cloud V17
SiemensSIMOTION SCOUT TIA V5.4
SiemensSIMATIC WinCC V19

…and 14 more

Timeline

References

Open in Interactive Console →