CVE-2021-40363
published 2022-02-09CVE-2021-40363: A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1)…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.16%
5.5th percentile
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (All versions < V16 Update 5), SIMATIC WinCC V17 (All versions < V17 Update 2), SIMATIC WinCC V17 (All versions <= V17 Update 4), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 19), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 6). The affected component stores the credentials of a local system account in a potentially publicly accessible project file using an outdated cipher algorithm. An attacker may use this to brute force the credentials and take over the system.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_pcs_7 | <= 8.2 | — |
| siemens | simatic_pcs_7 | — | — |
| siemens | simatic_pcs_7 | — | — |
| siemens | simatic_pcs_7_v8.2 | — | — |
| siemens | simatic_pcs_7_v9.0 | — | — |
| siemens | simatic_pcs_7_v9.1 | — | — |
| siemens | simatic_wincc | < 7.4 | 7.4 |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc_v15_and_earlier | — | — |
| siemens | simatic_wincc_v16 | — | — |
| siemens | simatic_wincc_v17 | — | — |
| siemens | simatic_wincc_v17 | — | — |
| siemens | simatic_wincc_v7.4 | — | — |
| siemens | simatic_wincc_v7.5 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wg4m-r562-77pw: A vulnerability has been identified in SIMATIC PCS 7 V8
ghsa_unreviewed·2022-02-10
CVE-2021-40363 [HIGH] CWE-312 GHSA-wg4m-r562-77pw: A vulnerability has been identified in SIMATIC PCS 7 V8
A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions = V17 Update 2), SIMATIC WinCC V7.4 and earlier (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 6). The affected component stores the credentials of a local system account in a potentially publicly accessible project file using an outdated cipher algorithm. An attacker may use this to brute force the credentials and take over the system.
CISA ICS
Siemens SIMATIC WinCC and PCS (Update C)
cisa_ics·2022-05-12·CVSS 7.8
[HIGH] Siemens SIMATIC WinCC and PCS (Update C)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC WinCC and PCS (Update C)
Last RevisedAugust 11, 2022
Alert CodeICSA-22-041-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC WinCC and PCS
- Vulnerabilities: Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Externally-Accessible File or Directory
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-22-041-02 Siemens SIMATIC WinCC and PCS (Update B) that was published May 12, 2022
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-09
Published