Vulnerability in SIMATIC NET and PCS 7 Software by Siemens
CVE-2023-28829

8.8HIGH

Key Information:

Summary

A significant vulnerability exists in Siemens' SIMATIC NET PC Software and PCS 7 Software, affecting various versions of these products. The issue arises from the use of legacy OPC services (including OPC DA, OPC HDA, and OPC AE), which were default settings prior to the release of SIMATIC WinCC V8. These services rely on the outdated Windows ActiveX and DCOM technologies, lacking modern security measures for authentication and data encryption. This oversight leaves systems at risk of unauthorized access and potential data breaches.

Affected Version(s)

SIMATIC NET PC Software V14 All versions

SIMATIC NET PC Software V15 All versions

SIMATIC PCS 7 V8.2 All versions

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.