VDB

SSA-871035

SSA-871035 PUBLISHED CVSS 7.300000190734863 HIGH

Affected products do not properly sanitize user-controllable input when parsing files. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected application. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens recommends countermeasures for products where fixes are not, or not yet available.

Risk Scores

CVSS v3.1
7.300000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
SIMOCODE ES V16
SIMATIC STEP 7 Safety V16
SIMATIC WinCC Unified V18
SIMATIC STEP 7 V18
SIMATIC STEP 7 Safety V18
SIMATIC WinCC V18
SIMOTION SCOUT TIA V5.4 SP1
SIMATIC WinCC V17
SIMOCODE ES V18
SIMOTION SCOUT TIA V5.4 SP3
SIMATIC STEP 7 V17
SIMATIC WinCC Unified V16
SIMATIC STEP 7 Safety V17
SIMOTION SCOUT TIA V5.5 SP1
SIMATIC STEP 7 V16
SIMOCODE ES V17
SIMATIC S7-PLCSIM V17
SIMATIC WinCC Unified V17
SIMATIC S7-PLCSIM V16
SIMATIC WinCC V16

Timeline

  • Nov 12, 2024 CVE Published
  • Jan 14, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›