CVE Database
/

CVE-2024-30321

Back to search

CVE-2024-30321

Published: Jul 9, 2024

Modified: Aug 27, 2025

PUBLISHED

CVSS v3.1

5.9

MEDIUM

Description

A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 5), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 2), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 23), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 17), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5). The affected products do not properly handle certain requests to their web application, which may lead to the leak of privileged information. This could allow an unauthenticated remote attacker to retrieve information such as users and passwords.

VendorProductVersions

Siemens

SIMATIC PCS 7 V9.1

affected
0 - < V9.1 SP2 UC05

Siemens

SIMATIC WinCC Runtime Professional V18

affected
0 - < V18 Update 5

Siemens

SIMATIC WinCC Runtime Professional V19

affected
0 - < V19 Update 2

Siemens

SIMATIC WinCC V7.4

affected
0 - < V7.4 SP1 Update 23

Siemens

SIMATIC WinCC V7.5

affected
0 - < V7.5 SP2 Update 17

Siemens

SIMATIC WinCC V8.0

affected
0 - < V8.0 Update 5

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now