

Rewterz Threat Advisory – Delta Industrial Automation CNCSoft ScreenEditor Multiple Vulnerabilities
July 12, 2019
Rewterz Threat Advisory – CVE-2019-10915 – Siemens TIA Administrator (TIA Portal) Improper Access Control Vulnerability
July 12, 2019
Rewterz Threat Advisory – Delta Industrial Automation CNCSoft ScreenEditor Multiple Vulnerabilities
July 12, 2019
Rewterz Threat Advisory – CVE-2019-10915 – Siemens TIA Administrator (TIA Portal) Improper Access Control Vulnerability
July 12, 2019Severity
Medium
Analysis Summary
The SIMATIC WinCC DataMonitor web application of the affected products allows an authenticated user with network access to the WinCC DataMonitor application to upload arbitrary ASPX code.
Successful exploitation requires no user interaction and may impact the confidentiality, integrity, and availability of the affected device. The vulnerability is relevant only in situations where an attacker has access via the web interface but not to the directory structure.
Impact
Exposure of sensitive information
Affected Vendors
Siemens
Affected Products
- SIMATIC WinCC and SIMATIC PCS7
- SIMATIC PCS 7 v8.0: all versions
- SIMATIC PCS 7 v8.1: all versions
- SIMATIC PCS 7 v8.2: all versions prior to v8.2 SP1 with WinCC v7.4 SP1 Upd 11
- SIMATIC PCS 7 v9.0: all versions prior to v9.0 SP2 with WinCC v7.4 SP1 Upd 11
- SIMATIC WinCC Professional (TIA Portal v13): all versions
- SIMATIC WinCC Professional (TIA Portal v14): all versions
- SIMATIC WinCC Professional (TIA Portal v15): all versions
- SIMATIC WinCC Runtime Professional v13: all versions
- SIMATIC WinCC Runtime Professional v14: all versions
- SIMATIC WinCC Runtime Professional v15: all versions
- SIMATIC WinCC v7.2 and earlier: all versions
- SIMATIC WinCC v7.3: all versions
- SIMATIC WinCC v7.4: all versions prior to v7.4 SP1 Upd 11
- SIMATIC WinCC v7.5: all versions prior to v7.5 Upd 3
Remediation
Siemens currently has updates for the following products:
SIMATIC PCS 7 v8.2: Update WinCC to v7.4 SP1 Upd 11
SIMATIC PCS 7 v9.0: Update WinCC to v7.4 SP1 Upd 11
SIMATIC WinCC v7.4: Update WinCC to v7.4 SP1 Upd 11
SIMATIC WinCC v7.5: Update WinCC to v7.5 Upd 3