Injection Flaw in SIMATIC WinCC OA from Siemens
CVE-2022-44731
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 13 December 2022
What is CVE-2022-44731?
A critical vulnerability has been detected in various versions of Siemens' SIMATIC WinCC OA. This flaw permits authenticated remote attackers to inject custom arguments into the Ultralight Client backend application through the web interface. If exploited, it can allow attackers to manipulate application behavior, including opening unauthorized panels or initiating scripts with the attacker's credentials, posing serious risks to operational integrity and data security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SIMATIC WinCC OA V3.15 All versions < V3.15 P038
SIMATIC WinCC OA V3.16 All versions < V3.16 P035
SIMATIC WinCC OA V3.17 All versions < V3.17 P024
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved