CVE-2019-10935
published 2019-07-11CVE-2019-10935: A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.3 Upd 19), SIMATIC…
PriorityP342high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
EPSS
1.30%
67.2th percentile
A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.3 Upd 19), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd 11), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP2 with WinCC V7.4 SP1 Upd11), SIMATIC WinCC Professional (TIA Portal V13) (All versions), SIMATIC WinCC Professional (TIA Portal V14) (All versions < V14 SP1 Upd 9), SIMATIC WinCC Professional (TIA Portal V15) (All versions < V15.1 Upd 3), SIMATIC WinCC Runtime Professional V13 (All versions), SIMATIC WinCC Runtime Professional V14 (All versions < V14.1 Upd 8), SIMATIC WinCC Runtime Professional V15 (All versions < V15.1 Upd 3), SIMATIC WinCC V7.2 and earlier (All versions), SIMATIC WinCC V7.3 (All versions < V7.3 Upd 19), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Upd 11), SIMATIC WinCC V7.5 (All versions < V7.5 Upd 3). The SIMATIC WinCC DataMonitor web application of the affected products allows to upload arbitrary ASPX code. The security vulnerability could be exploited by an authenticated attacker with network access to the WinCC DataMonitor application. No user interaction is required to exploit this vulnerability. The vulnerability impacts confidentiality, integrity, and availability of the affected device. At the stage of publishing this security advisory no public exploitation is known.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_pcs_7 | — | — |
| siemens | simatic_pcs_7 | — | — |
| siemens | simatic_pcs_7 | — | — |
| siemens | simatic_pcs_7 | — | — |
| siemens | simatic_wincc | <= 7.2 | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc_runtime | — | — |
| siemens | simatic_wincc_runtime | — | — |
| siemens | simatic_wincc_runtime | — | — |
| siemens | simatic_wincc_runtime | — | — |
| siemens_ag | simatic_pcs_7_v8.0_and_earlier | — | — |
| siemens_ag | simatic_pcs_7_v8.1 | — | — |
| siemens_ag | simatic_pcs_7_v8.2 | — | — |
| siemens_ag | simatic_pcs_7_v9.0 | — | — |
| siemens_ag | simatic_wincc_professional | — | — |
| siemens_ag | simatic_wincc_professional | — | — |
| siemens_ag | simatic_wincc_professional | — | — |
| siemens_ag | simatic_wincc_runtime_professional_v13 | — | — |
| siemens_ag | simatic_wincc_runtime_professional_v14 | — | — |
| siemens_ag | simatic_wincc_runtime_professional_v15 | — | — |
CVSS provenance
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3hg6-vvm5-64f6: A vulnerability has been identified in SIMATIC PCS 7 V8
ghsa_unreviewed·2022-05-24
CVE-2019-10935 [HIGH] CWE-434 GHSA-3hg6-vvm5-64f6: A vulnerability has been identified in SIMATIC PCS 7 V8
A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd11), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP2 with WinCC V7.4 SP1 Upd11), SIMATIC WinCC Professional (TIA Portal V13) (All versions), SIMATIC WinCC Professional (TIA Portal V14) (All versions), SIMATIC WinCC Professional (TIA Portal V15) (All versions), SIMATIC WinCC Runtime Professional V13 (All versions), SIMATIC WinCC Runtime Professional V14 (All versions), SIMATIC WinCC Runtime Professional V15 (All versions), SIMATIC WinCC V7.2 and earlier (All versions), SIMATIC WinCC V7.3 (All versions), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Upd 11), SIMATIC WinCC V7.5 (All versions < V7.5 Upd 3). The SIM
CISA ICS
Siemens SIMATIC WinCC and PCS7 (Update C)
cisa_ics·2019-09-10
Siemens SIMATIC WinCC and PCS7 (Update C)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC WinCC and PCS7 (Update C)
Last RevisedOctober 10, 2019
Alert CodeICSA-19-192-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.2
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: SIMATIC WinCC and SIMATIC PCS7
- Vulnerability: Unrestricted Upload of File with Dangerous Type
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-19-192-02 Siemens SIMATIC WinCC and PCS7 (Update B) that was published September 10, 2019, on the ICS webpage of us-cert.gov.
## 3. RISK EVALUATION
Successful
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-07-11
Published