Risk Scores
CVSS v3.1
7.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SIMATIC PCS neo V4.1 | ||
| SIMATIC WinCC Runtime Professional V19 | ||
| SIMATIC WinCC V8.0 | ||
| SIMATIC PCS neo V5.0 | ||
| SIMATIC WinCC Runtime Professional V17 | ||
| Data Flow Monitoring Industrial Edge Device User Interface (DFM IED UI) | ||
| LiveTwin Industrial Edge app (6AV2170-0BL00-0AA0) | ||
| SIMATIC WinCC V7.5 | ||
| SIMATIC WinCC Runtime Professional V18 | ||
| SIMATIC WinCC V7.4 | ||
| TIA Administrator | ||
| AI Model Deployer |
Timeline
- Sep 10, 2024 CVE Published
- Jan 14, 2025 CVE Updated
References
- https://cert-portal.siemens.com/productcert/html/ssa-773256.html advisory
- https://cert-portal.siemens.com/productcert/csaf/ssa-773256.json advisory
- https://iehub.eu1.edge.siemens.cloud/ fix
- https://support.industry.siemens.com/cs/ww/en/view/109977244/ fix
- https://support.industry.siemens.com/cs/ww/en/view/109793460/ fix