cbcvebase.

Siemens Simatic Wincc vulnerabilities

38 known vulnerabilities affecting siemens/simatic_wincc.

Total CVEs
38
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH19MEDIUM14

Vulnerabilities

Page 1 of 2
CVE-2010-2772P2HIGHCVSS 7.8Exploitedv6.2v7.02010-07-22
CVE-2010-2772 [HIGH] CVE-2010-2772: Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568.
nvd
CVE-2019-10922P2CRITICALCVSS 9.8≤ 7.2≥ 7.32019-05-14
CVE-2019-10922 [CRITICAL] CWE-306 CVE-2019-10922: A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 and newer (All versions), SIMATIC WinCC V7.2 and earlier (All versions), SIMATIC WinCC V7.3 and newer (All versions). An attacker with network access to affected installations, which are configured without "Encrypted Communication", can execute
nvd
CVE-2016-5743P2CRITICALCVSS 9.8≤ 7.3≤ 7.42016-07-22
CVE-2016-5743 [CRITICAL] CWE-20 CVE-2016-5743: Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Upd Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Update 9 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.1 Update 3 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.2 Update 1 as distributed in SIMATIC PCS 7 8.2, and SIMATIC WinCC Runtime Professio
nvd
CVE-2019-6572P2CRITICALCVSS 9.1fixed in 15.12019-05-14
CVE-2019-6572 [CRITICAL] CWE-200 CVE-2019-6572: A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Upd A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15.1 Update 1), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 und KTP900F (All versions < V15.1 Update 1), SIMATIC WinCC Runtime Advanced (All versions < V15.1 Updat
nvd
CVE-2019-10918P3HIGHCVSS 8.8≤ 7.2v7.3+5 more2019-05-14
CVE-2019-10918 [HIGH] CWE-749 CVE-2019-10918: A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.3 Upd 19), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd11), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP2 with WinCC V7.4 SP1 Upd11), SIMATIC WinCC (TIA Portal) V13 (All versions), SIMATIC WinC
nvd
CVE-2014-8551P3CRITICALCVSS 10.0v7.0v7.2+1 more2014-11-26
CVE-2014-8551 [CRITICAL] CWE-94 CVE-2014-8551: The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Updat The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to execute arbitrary code via crafted packets.
nvd
CVE-2021-40358P3CRITICALCVSS 9.8v7.4v7.5+4 more2021-11-09
CVE-2021-40358 [CRITICAL] CWE-22 CVE-2021-40358: A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All ve A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC04), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (All versions < V16 Update 5), SIMATIC WinCC V17 (All versions < V17 Update 2), SIMATIC WinCC V7
nvd
CVE-2019-10916P3HIGHCVSS 8.8≤ 7.2v7.3+5 more2019-05-14
CVE-2019-10916 [HIGH] CWE-89 CVE-2019-10916: A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.3 Upd 19), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd11), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP2 with WinCC V7.4 SP1 Upd11), SIMATIC WinCC (TIA Portal) V13 (All versions), SIMATIC WinCC
nvd
CVE-2018-13814P3HIGHCVSS 8.8fixed in 14.02018-12-13
CVE-2018-13814 [HIGH] CWE-113 CVE-2018-13814: A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIM A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V14), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V14), SIMATIC WinCC Runtime Advanced (All versions < V14), SIMATIC WinCC Runtime Professional (All
nvd
CVE-2018-13812P3HIGHCVSS 7.5≤ 15.02018-12-13
CVE-2018-13812 [HIGH] CWE-22 CVE-2018-13812: A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Updat A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15 Update 4), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15 Update 4), SIMATIC WinCC Runtime Advanced (All versions < V15 Update 4), SIMAT
nvd
CVE-2023-28829P3HIGHCVSS 8.8fixed in 8.0vAll versions < V8.02023-06-13
CVE-2023-28829 [HIGH] CWE-477 CVE-2023-28829: A vulnerability has been identified in SIMATIC NET PC Software V14 (All versions), SIMATIC NET PC So A vulnerability has been identified in SIMATIC NET PC Software V14 (All versions), SIMATIC NET PC Software V15 (All versions), SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC WinCC (All versions < V8.0), SINAUT Software ST7sc (All versions). Before SIMATIC WinCC V8, legacy OPC services (
nvd
CVE-2021-40360P3HIGHCVSS 8.8fixed in 7.4v7.4+7 more2022-02-09
CVE-2021-40360 [HIGH] CWE-200 CVE-2021-40360: A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All ve A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (All versions < V16 Update 5), SIMATIC WinCC V17 (All versions < V17 Update 2), SIMATIC WinCC V7.4 (All versions <
nvd
CVE-2016-5744P3HIGHCVSS 7.5v7.0v7.22016-07-22
CVE-2016-5744 [HIGH] CWE-200 CVE-2016-5744: Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC statio Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC station files via crafted packets.
nvd
CVE-2018-13813P3HIGHCVSS 8.1≤ 15.02018-12-13
CVE-2018-13813 [HIGH] CWE-601 CVE-2018-13813: A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Updat A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15 Update 4), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15 Update 4), SIMATIC WinCC Runtime Advanced (All versions < V15 Update 4), SIMA
nvd
CVE-2018-4832P3HIGHCVSS 7.5fixed in 7.2v7.2+2 more2018-04-24
CVE-2018-4832 [HIGH] CWE-20 CVE-2018-4832: A vulnerability has been identified in OpenPCS 7 V7.1 and earlier (All versions), OpenPCS 7 V8.0 (Al A vulnerability has been identified in OpenPCS 7 V7.1 and earlier (All versions), OpenPCS 7 V8.0 (All versions), OpenPCS 7 V8.1 (All versions < V8.1 Upd5), OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd1), SIMATIC BATCH V7.1 and earlier (All versions), SIMATIC BATCH V8.0 (All versions < V8.0 SP1 Upd21), SIMATIC BATCH V8.1 (All ver
nvd
CVE-2021-40359P3HIGHCVSS 7.5≤ 7.4v7.5+3 more2021-11-09
CVE-2021-40359 [HIGH] CWE-22 CVE-2021-40359: A vulnerability has been identified in OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < A vulnerability has been identified in OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd4), OpenPCS 7 V9.1 (All versions), SIMATIC BATCH V8.2 (All versions), SIMATIC BATCH V9.0 (All versions), SIMATIC BATCH V9.1 (All versions), SIMATIC NET PC Software V14 (All versions), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC So
nvd
CVE-2019-10935P3HIGHCVSS 7.2≤ 7.2v7.3+5 more2019-07-11
CVE-2019-10935 [HIGH] CWE-434 CVE-2019-10935: A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.3 Upd 19), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd 11), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP2 with WinCC V7.4 SP1 Upd11), SIMATIC WinCC Professional (TIA Portal V13) (All versions)
nvd
CVE-2023-30897P3HIGHCVSS 7.8vAll versions < V7.5.2.132023-06-13
CVE-2023-30897 [HIGH] CWE-732 CVE-2023-30897: A vulnerability has been identified in SIMATIC WinCC (All versions < V7.5.2.13). Affected applicatio A vulnerability has been identified in SIMATIC WinCC (All versions < V7.5.2.13). Affected applications fail to set proper access rights for their installation folder if a non-default installation path was chosen during installation. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.
nvd
CVE-2019-19282P3HIGHCVSS 7.5v7.4v7.5+5 more2020-03-10
CVE-2019-19282 [HIGH] CWE-131 CVE-2019-19282: A vulnerability has been identified in OpenPCS 7 V8.1 (All versions), OpenPCS 7 V8.2 (All versions), A vulnerability has been identified in OpenPCS 7 V8.1 (All versions), OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd3), SIMATIC BATCH V8.1 (All versions), SIMATIC BATCH V8.2 (All versions < V8.2 Upd12), SIMATIC BATCH V9.0 (All versions < V9.0 SP1 Upd5), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET
nvd
CVE-2018-11454P3HIGHCVSS 8.6v10.0v11.0+4 more2018-08-07
CVE-2018-11454 [HIGH] CWE-276 CVE-2018-11454: A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 6), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V15
nvd
Siemens Simatic Wincc vulnerabilities | cvebase