7.2

CVE-2019-10935

A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.3 Upd 19), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd 11), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP2 with WinCC V7.4 SP1 Upd11), SIMATIC WinCC Professional (TIA Portal V13) (All versions), SIMATIC WinCC Professional (TIA Portal V14) (All versions < V14 SP1 Upd 9), SIMATIC WinCC Professional (TIA Portal V15) (All versions < V15.1 Upd 3), SIMATIC WinCC Runtime Professional V13 (All versions), SIMATIC WinCC Runtime Professional V14 (All versions < V14.1 Upd 8), SIMATIC WinCC Runtime Professional V15 (All versions < V15.1 Upd 3), SIMATIC WinCC V7.2 and earlier (All versions), SIMATIC WinCC V7.3 (All versions < V7.3 Upd 19), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Upd 11), SIMATIC WinCC V7.5 (All versions < V7.5 Upd 3). The SIMATIC WinCC DataMonitor web application of the affected products allows to upload arbitrary ASPX code. The security vulnerability could be exploited by an authenticated attacker with network access to the WinCC DataMonitor application. No user interaction is required to exploit this vulnerability. The vulnerability impacts confidentiality, integrity, and availability of the affected device. At the stage of publishing this security advisory no public exploitation is known.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Simatic Pcs 7 Version 8.0
Siemens ≫ Simatic Pcs 7 Version 8.1
Siemens ≫ Simatic Pcs 7 Version 8.2
Siemens ≫ Simatic Pcs 7 Version 9.0
Siemens ≫ Simatic Wincc Version <= 7.2
Siemens ≫ Simatic Wincc Version 7.3 Update -
Siemens ≫ Simatic Wincc Version 7.3 Update update_1
Siemens ≫ Simatic Wincc Version 7.3 Update update_10
Siemens ≫ Simatic Wincc Version 7.3 Update update_11
Siemens ≫ Simatic Wincc Version 7.3 Update update_13
Siemens ≫ Simatic Wincc Version 7.3 Update update_4
Siemens ≫ Simatic Wincc Version 7.4 Update -
Siemens ≫ Simatic Wincc Version 7.4 Update sp1
Siemens ≫ Simatic Wincc Version 7.4 Update update_1
Siemens ≫ Simatic Wincc Version 7.5
Siemens ≫ Simatic Wincc Version 13 Update - SwEdition professional
Siemens ≫ Simatic Wincc Version 13 Update sp2 SwEdition professional
Siemens ≫ Simatic Wincc Version 14 SwEdition professional
Siemens ≫ Simatic Wincc Version 14 Update - SwEdition professional
Siemens ≫ Simatic Wincc Version 14 Update sp1 SwEdition professional
Siemens ≫ Simatic Wincc Version 15 SwEdition professional
Siemens ≫ Simatic Wincc Runtime Version 13 SwEdition professional
Siemens ≫ Simatic Wincc Runtime Version 13 Update - SwEdition professional
Siemens ≫ Simatic Wincc Runtime Version 13 Update sp1 Edition update_2 SwEdition professional
Siemens ≫ Simatic Wincc Runtime Version 13 Update sp1 Edition update_9 SwEdition professional
Siemens ≫ Simatic Wincc Runtime Version 13 Update sp2 SwEdition professional
Siemens ≫ Simatic Wincc Runtime Version 14 Update - SwEdition professional
Siemens ≫ Simatic Wincc Runtime Version 14 Update sp1 SwEdition professional
Siemens ≫ Simatic Wincc Runtime Version 15 Update - SwEdition professional
Siemens ≫ Simatic Wincc Runtime Version 15 Update update_4 SwEdition professional
Siemens ≫ Simatic Wincc Runtime Version 15.1 Update - SwEdition professional
Siemens ≫ Simatic Wincc Runtime Version 15.1 Update update_1 SwEdition professional
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.3% 0.666
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://cert-portal.siemens.com/productcert/pdf/ssa-121293.pdf
Patch
Vendor Advisory