Vulnerability in Siemens SIMATIC Products Allows Kiosk Mode Escape
CVE-2022-24287

7.8HIGH

Key Information:

Summary

A security flaw in Siemens' SIMATIC products allows an authenticated attacker to bypass the Kiosk Mode due to a missing printer configuration on the host. This vulnerability affects various versions of the SIMATIC PCS 7 and WinCC products, which could potentially lead to unauthorized access and manipulation of the systems. It is critical for users to ensure correct printer configurations to mitigate this risk effectively.

Affected Version(s)

SIMATIC PCS 7 V8.2 All versions

SIMATIC PCS 7 V9.0 All versions < V9.0 SP3 UC06

SIMATIC PCS 7 V9.1 All versions < V9.1 SP1 UC01

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.