ICSA-20-161-04: Siemens SIMATIC Automation Tool vulnerability

Affected Software

31 affected componentsFixes available
Siemens SIMATIC Automation Tool
Siemens SIMATIC NET PC software: All versions after v16 and prior to v16 Upd3
Siemens SIMATIC PCS neo SP1<3.0
3.0
Siemens SIMATIC ProSave
Siemens SIMATIC S7-1500 Software Controller<21.8
21.8
Siemens SINAMICS STARTER HF2<5.4
5.4
Siemens SIMATIC STEP 7 SP2 HF3<5.6
5.6
Siemens SIMATIC STEP 7 (TIA Portal) v13: All versions prior to SP2 Update 4
Siemens SIMATIC STEP 7 (TIA Portal) v14 SP1 Update 10<14
14
Siemens SIMATIC WinCC Runtime Professional v14 SP1 Update 10<14
14
Siemens SIMATIC STEP 7 (TIA Portal) v15: All versions prior to v15.1 Update 5
Siemens SIMATIC STEP 7 (TIA Portal) v16 Update 2<16
16
Siemens SIMATIC WinCC OA v3.16: All versions prior to P018
Siemens SIMATIC WinCC OA v3.17: All versions prior to P003
Siemens SIMATIC WinCC Runtime Advanced Update 2<16
16
Siemens SIMATIC WinCC Runtime Professional v13 SP2 Update 4<13
13
Siemens SIMATIC WinCC Runtime Professional v14
Siemens SIMATIC WinCC Runtime Professional v15 Update 5<15.1
15.1
Siemens SIMATIC WinCC Runtime Professional v16 Update 2<16
16
Siemens SIMATIC WinCC v7.4 SP1 Update 14<7.4
7.4
Siemens SIMATIC WinCC v7.5 SP1 Update 3<7.5
7.5
Siemens SINAMICS Startdrive
Siemens SINEMA Server SP3<14
14
Siemens SIMATIC ProSave<17
17
Siemens SIMATIC NET PC software v14 Update 14<14
14
Siemens SIMATIC NET PC software v15
Siemens SIMATIC NET PC software v16 Upd3<16
16
Siemens SINUMERIK ONE virtual<6.14
6.14
Siemens SINUMERIK Operate<6.14
6.14
Siemens SIMATIC Automation Tool SP2<4
4
Siemens SINEC NMS SP2<1.0
1.0

Event History

Feb 24, 2026
Advisory Published
12:32 AM
Data Sourced
12:32 AM
Affected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of ICSA-20-161-04?

The severity level of ICSA-20-161-04 is classified as critical due to the potential for remote code execution.

2

How do I fix ICSA-20-161-04?

To fix ICSA-20-161-04, users should upgrade to the latest version or apply the necessary patches as specified by Siemens.

3

What systems are affected by ICSA-20-161-04?

ICSA-20-161-04 affects multiple Siemens software products, including Siemens SIMATIC ProSave and others listed in the advisory.

4

Is there a workaround for ICSA-20-161-04?

Currently, there are no specific workarounds recommended for mitigating ICSA-20-161-04; patching is advised.

5

What types of vulnerabilities are described in ICSA-20-161-04?

ICSA-20-161-04 describes vulnerabilities that could lead to remote code execution on affected Siemens software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203