A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verification process, an attacker could bypass the password protection set on protected files, thus being granted access to the protected content, circumventing authentication.
Software | From | Fixed in |
---|---|---|
siemens / simatic_wincc | - | 7.5 |
siemens / simatic_wincc | 7.5-sp1 | 7.5-sp1.x |
siemens / simatic_wincc | 7.5-sp1_update1 | 7.5-sp1_update1.x |
siemens / simatic_wincc | 7.5-sp1_update2 | 7.5-sp1_update2.x |
siemens / simatic_pcs_7 | - | - |