A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions), SIMATIC Information Server 2022 (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC Process Historian 2020 (All versions), SIMATIC Process Historian 2022 (All versions), SIMATIC WinCC Runtime Professional V18 (All versions), SIMATIC WinCC Runtime Professional V19 (All versions), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 18), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5). The affected products run their DB server with elevated privileges which could allow an authenticated attacker to execute arbitrary OS commands with administrative privileges.
History

Tue, 10 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens simatic Batch
Siemens simatic Information Server
Siemens simatic Pcs7
Siemens simatic Process Historian
Siemens simatic Wincc
Siemens simatic Wincc Runtime Professional
CPEs cpe:2.3:a:siemens:simatic_batch:9.1:-:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_information_server:2020:-:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_information_server:2022:*:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_pcs7:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_process_historian:2022:*:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_wincc:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_wincc_runtime_professional:18:*:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_wincc_runtime_professional:19:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_process_historian:2020:-:*:*:*:*:*:*
Vendors & Products Siemens
Siemens simatic Batch
Siemens simatic Information Server
Siemens simatic Pcs7
Siemens simatic Process Historian
Siemens simatic Wincc
Siemens simatic Wincc Runtime Professional
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Sep 2024 09:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions), SIMATIC Information Server 2022 (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC Process Historian 2020 (All versions), SIMATIC Process Historian 2022 (All versions), SIMATIC WinCC Runtime Professional V18 (All versions), SIMATIC WinCC Runtime Professional V19 (All versions), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 18), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5). The affected products run their DB server with elevated privileges which could allow an authenticated attacker to execute arbitrary OS commands with administrative privileges.
Weaknesses CWE-250
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2024-09-10T09:36:32.225Z

Updated: 2024-09-10T17:31:08.389Z

Reserved: 2024-05-17T11:07:53.264Z

Link: CVE-2024-35783

cve-icon Vulnrichment

Updated: 2024-09-10T17:08:22.704Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-10T10:15:09.937

Modified: 2024-09-10T12:09:50.377

Link: CVE-2024-35783

cve-icon Redhat

No data.