← Back

CVE-2022-24287

nvd nist
Published: May 20, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD (Secondary)

Description

A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC06), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1 UC01), SIMATIC WinCC Runtime Professional V16 and earlier (All versions), SIMATIC WinCC Runtime Professional V17 (All versions < V17 Upd4), SIMATIC WinCC V7.3 (All versions), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 21), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 8). A missing printer configuration on the host could allow an authenticated attacker to escape the WinCC Kiosk Mode.

Affected (17)

3 products
Simatic Pcs 7
Simatic Wincc
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Siemens
Up to 9.0
Version 9.1
Siemens
Up to 7.4
Version 7.5
Version 7.5 sp1
Version 7.5 sp1_update1
Version 7.5 sp1_update2
Version 7.5 sp2
Version 7.5 sp2_update1
Version 7.5 sp2_update2
Version 7.5 sp2_update3
Version 7.5 sp2_update4
Version 7.5 sp2_update5
Version 7.5 sp2_update6
Version 7.5 sp2_update7
Siemens
Up to 16
Version 17

References (2)

Source: productcert@siemens.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.