You are here

Siemens SIMATIC WinCC OA (ICSA-18-254-04) – Product Used in the Water and Wastewater and Energy Sectors

Siemens SIMATIC WinCC OA (ICSA-18-254-04) – Product Used in the Water and Wastewater and Energy Sectors

Created: Tuesday, September 11, 2018 - 17:24
Categories:
Cybersecurity

The NCCIC has released an advisory on an uncontrolled search path element vulnerability in Siemens SIMATIC WinCC OA. SIMATIC WinCC OA Version 3.14 and prior are affected. Successful exploitation of this vulnerability could allow an unauthenticated remote user to escalate their privileges in the context of the program. Siemens recommends updating to SIMATIC WinCC OA v3.14-P021 and a series of manual mitigations to reduce risks. The NCCIC also recommends a series of defensive measures to minimize the risk of exploitation of these vulnerabilities. NCCIC/ICS-CERT.