CVE-2024-30321

July 9, 2024, 6:19 p.m.

Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

SIMATIC PCS 7

  • 9.1

SIMATIC WinCC Runtime Professional

  • 18
  • 19 < 19 Update 2

SIMATIC WinCC V7.4

  • 7.4 < 7.4 SP1 Update 23

SIMATIC WinCC V7.5

  • 7.5 < 7.5 SP2 Update 17

SIMATIC WinCC V8.0

  • 8.0 < 8.0 Update 5

Source

productcert@siemens.com

Tags

CVE-2024-30321 details

Published : July 9, 2024, 12:15 p.m.
Last Modified : July 9, 2024, 6:19 p.m.

Description

A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions), SIMATIC WinCC Runtime Professional V18 (All versions), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 2), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 23), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 17), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5). The affected products do not properly handle certain requests to their web application, which may lead to the leak of privileged information. This could allow an unauthenticated remote attacker to retrieve information such as users and passwords.

CVSS Score

1 2 3 4 5.9 6 7 8 9 10

Weakness

Weakness Name Description
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

CVSS Data

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

Base Score

5.9

Exploitability Score

2.2

Impact Score

3.6

Base Severity

MEDIUM

References

URL Source
https://cert-portal.siemens.com/productcert/html/ssa-883918.html productcert@siemens.com
This website uses the NVD API, but is not approved or certified by it.