SSA-691715 PUBLISHED CVSS 7.800000190734863 HIGH

OPC Foundation Local Discovery Server (LDS) in affected products uses a hard-coded file path to a configuration file. This allows a normal user to create a malicious file that is loaded by LDS (running as a high-privilege user).

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
SiemensSIMATIC WinCC
SiemensSIMATIC WinCC Unified PC Runtime V18
SiemensSIMATIC NET PC Software V16
SiemensSIMATIC NET PC Software V14
SiemensSIMATIC NET PC Software V17
SiemensSIMATIC NET PC Software V18
SiemensSIMATIC WinCC Runtime Professional
SiemensSIMATIC NET PC Software V15
SiemensSIMATIC Process Historian 2022 OPC UA Server
SiemensSIMATIC Process Historian 2020 OPC UA Server
SiemensTeleControl Server Basic V3
SiemensOpenPCS 7 V9.1

Timeline

References

Open in Interactive Console →