CVE Database
/

CVE-2024-35783

Back to search

CVE-2024-35783

Published: Sep 10, 2024

Modified: Jan 14, 2025

PUBLISHED

CVSS v3.1

9.1

CRITICAL

Description

A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server 2022 (All versions < V2022 SP1 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC06), SIMATIC Process Historian 2020 (All versions < V2020 SP2 Update 5), SIMATIC Process Historian 2022 (All versions < V2022 SP1 Update 2), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 5), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 3), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 18), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5). The affected products run their DB server with elevated privileges which could allow an authenticated attacker to execute arbitrary OS commands with administrative privileges.

VendorProductVersions

Siemens

SIMATIC BATCH V9.1

affected
0 - < *

Siemens

SIMATIC Information Server 2020

affected
0 - < V2020 SP2 Update 5

Siemens

SIMATIC Information Server 2022

affected
0 - < V2022 SP1 Update 2

Siemens

SIMATIC PCS 7 V9.1

affected
0 - < V9.1 SP2 UC06

Siemens

SIMATIC Process Historian 2020

affected
0 - < V2020 SP2 Update 5

Siemens

SIMATIC Process Historian 2022

affected
0 - < V2022 SP1 Update 2

Siemens

SIMATIC WinCC Runtime Professional V18

affected
0 - < V18 Update 5

Siemens

SIMATIC WinCC Runtime Professional V19

affected
0 - < V19 Update 3

Siemens

SIMATIC WinCC V7.4

affected
0 - < *

Siemens

SIMATIC WinCC V7.5

affected
0 - < V7.5 SP2 Update 18

Siemens

SIMATIC WinCC V8.0

affected
0 - < V8.0 Update 5

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C

Attack Vector

Network

Attack Complexity

Low

Privileges Required

High

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now