First published: Tue Aug 07 2018(Updated: )
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 6), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V15 (All versions < V15 Update 2). Improper file permissions in the default installation of TIA Portal may allow an attacker with local file system access to manipulate resources which may be transferred to devices and executed there by a different user. No special privileges are required, but the victim needs to transfer the manipulated files to a device. Execution is caused on the target device rather than on the PG device.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SIMATIC STEP 7 (TIA Portal) | =10.0 | |
Siemens SIMATIC STEP 7 (TIA Portal) | =11.0 | |
Siemens SIMATIC STEP 7 (TIA Portal) | =12.0 | |
Siemens SIMATIC STEP 7 (TIA Portal) | =13.0 | |
Siemens SIMATIC STEP 7 (TIA Portal) | =13.0-sp1 | |
Siemens SIMATIC STEP 7 (TIA Portal) | =14.0 | |
Siemens SIMATIC STEP 7 (TIA Portal) | =15.0 | |
Siemens SIMATIC WinCC (TIA Portal) | =10.0 | |
Siemens SIMATIC WinCC (TIA Portal) | =11.0 | |
Siemens SIMATIC WinCC (TIA Portal) | =12.0 | |
Siemens SIMATIC WinCC (TIA Portal) | =13.0 | |
Siemens SIMATIC WinCC (TIA Portal) | =14.0 | |
Siemens SIMATIC WinCC (TIA Portal) | =15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-11454 is high, indicating significant risk to affected systems.
To fix CVE-2018-11454, users should update their versions of SIMATIC STEP 7 and WinCC (TIA Portal) to the latest releases or applicable patches provided by Siemens.
CVE-2018-11454 affects multiple versions of SIMATIC STEP 7 and WinCC (TIA Portal), specifically versions 10.0 through 15.0, with certain service packs being impacted.
CVE-2018-11454 is a security vulnerability that potentially allows unauthorized access or manipulation of protected data within the affected Siemens software.
There may be temporary workarounds, but the most effective solution is to apply the recommended security updates from Siemens for CVE-2018-11454.