CVE-2022-24287

HIGH

SIMATIC PCS 7 & WinCC - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC06), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1 UC01), SIMATIC WinCC Runtime Professional V16 and earlier (All versions), SIMATIC WinCC Runtime Professional V17 (All versions < V17 Upd4), SIMATIC WinCC V7.3 (All versions), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 21), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 8). A missing printer configuration on the host could allow an authenticated attacker to escape the WinCC Kiosk Mode.

Scores

CVSS v3 7.8
EPSS 0.0006
EPSS Percentile 17.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1188
Status published
Products (6)
siemens/simatic_pcs_7 9.1
siemens/simatic_pcs_7 < 9.0
siemens/simatic_wincc 7.5 (12 CPE variants)
siemens/simatic_wincc < 7.4
siemens/simatic_wincc_runtime_professional 17
siemens/simatic_wincc_runtime_professional < 16
Published May 20, 2022
Tracked Since Feb 18, 2026