Denial-of-Service Vulnerability in SIMATIC PCS 7 and WinCC Products by Siemens
CVE-2019-10917
5.5MEDIUM
Key Information:
- Vendor
- Siemens Ag
- Vendor
- CVE Published:
- 14 May 2019
Summary
A vulnerability in Siemens SIMATIC PCS 7 and WinCC products allows an attacker with local access to a project file to trigger a Denial-of-Service condition during the loading process. This could compromise the availability of the affected systems. Exploitation requires access to the project file, and there were no known public exploits at the time of the advisory publication.
Affected Version(s)
SIMATIC PCS 7 V8.0 and earlier All versions
SIMATIC PCS 7 V8.1 All versions < V8.1 with WinCC V7.3 Upd 19
SIMATIC PCS 7 V8.2 All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd11
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved