SSA-493396 PUBLISHED CVSS 7.800000190734863 HIGH

Affected products do not properly sanitize stored security properties when parsing project files. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected application.

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
SiemensSINAMICS Startdrive V19
SiemensSIMOCODE ES V18
SiemensSIMOCODE ES V19
SiemensSIRIUS Soft Starter ES V17 (TIA Portal)
SiemensTIA Portal Cloud V18
SiemensSIMOTION SCOUT TIA V5.7
SiemensSIRIUS Safety ES V19 (TIA Portal)
SiemensSIRIUS Soft Starter ES V19 (TIA Portal)
SiemensSINAMICS Startdrive V20
SiemensSIMATIC STEP 7 V20
SiemensTIA Portal Cloud V17
SiemensSIMATIC WinCC V19
SiemensSIRIUS Safety ES V17 (TIA Portal)
SiemensTIA Portal Cloud V19
SiemensSIMOCODE ES V20
SiemensSIMOTION SCOUT TIA V5.4
SiemensSIRIUS Soft Starter ES V18 (TIA Portal)
SiemensSIRIUS Safety ES V18 (TIA Portal)
SiemensSIMATIC WinCC V17
SiemensSIMOTION SCOUT TIA V5.5

…and 13 more

Timeline

References

Open in Interactive Console →