Network Access Vulnerability in Siemens SIMATIC HMI Devices and WinCC Products
CVE-2019-6576
7.5HIGH
Key Information:
What is CVE-2019-6576?
A vulnerability in Siemens SIMATIC HMI devices and WinCC products allows an attacker with network access to obtain TLS session keys. This could enable decryption of sensitive TLS traffic between legitimate users and the affected device. The flaw is present in multiple models and versions, posing risks to the confidentiality of communications. At the time of this advisory, there were no known public exploits related to this vulnerability.
Affected Version(s)
SIMATIC HMI Classic Devices (TP/MP/OP/MP Mobile Panel) All versions
SIMATIC HMI Comfort Outdoor Panels 7" & 15" All versions < V15.1 Update 1
SIMATIC HMI Comfort Panels 4" - 22" All versions < V15.1 Update 1