Vulnerability in Siemens SIMATIC Products Allows Kiosk Mode Escape
CVE-2022-24287
7.8HIGH
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 20 May 2022
Summary
A security flaw in Siemens' SIMATIC products allows an authenticated attacker to bypass the Kiosk Mode due to a missing printer configuration on the host. This vulnerability affects various versions of the SIMATIC PCS 7 and WinCC products, which could potentially lead to unauthorized access and manipulation of the systems. It is critical for users to ensure correct printer configurations to mitigate this risk effectively.
Affected Version(s)
SIMATIC PCS 7 V8.2 All versions
SIMATIC PCS 7 V9.0 All versions < V9.0 SP3 UC06
SIMATIC PCS 7 V9.1 All versions < V9.1 SP1 UC01
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved