A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions), SIMATIC Information Server 2022 (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC Process Historian 2020 (All versions), SIMATIC Process Historian 2022 (All versions), SIMATIC WinCC Runtime Professional V18 (All versions), SIMATIC WinCC Runtime Professional V19 (All versions), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 18), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5). The affected products run their DB server with elevated privileges which could allow an authenticated attacker to execute arbitrary OS commands with administrative privileges.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Siemens
Siemens simatic Batch Siemens simatic Information Server Siemens simatic Pcs7 Siemens simatic Process Historian Siemens simatic Wincc Siemens simatic Wincc Runtime Professional |
|
CPEs | cpe:2.3:a:siemens:simatic_batch:9.1:-:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_information_server:2020:-:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_information_server:2022:*:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_pcs7:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_process_historian:2022:*:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_wincc:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_wincc_runtime_professional:18:*:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_wincc_runtime_professional:19:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_process_historian:2020:-:*:*:*:*:*:* |
|
Vendors & Products |
Siemens
Siemens simatic Batch Siemens simatic Information Server Siemens simatic Pcs7 Siemens simatic Process Historian Siemens simatic Wincc Siemens simatic Wincc Runtime Professional |
|
Metrics |
ssvc
|
Tue, 10 Sep 2024 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions), SIMATIC Information Server 2022 (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC Process Historian 2020 (All versions), SIMATIC Process Historian 2022 (All versions), SIMATIC WinCC Runtime Professional V18 (All versions), SIMATIC WinCC Runtime Professional V19 (All versions), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 18), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5). The affected products run their DB server with elevated privileges which could allow an authenticated attacker to execute arbitrary OS commands with administrative privileges. | |
Weaknesses | CWE-250 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: siemens
Published: 2024-09-10T09:36:32.225Z
Updated: 2024-09-10T17:31:08.389Z
Reserved: 2024-05-17T11:07:53.264Z
Link: CVE-2024-35783
Vulnrichment
Updated: 2024-09-10T17:08:22.704Z
NVD
Status : Awaiting Analysis
Published: 2024-09-10T10:15:09.937
Modified: 2024-09-10T12:09:50.377
Link: CVE-2024-35783
Redhat
No data.