Siemens WinCC Certificate Manager

View CSAF

Summary

WinCC Certificate Manager insufficiently protects key material that could allow an attacker to extract sensitive information. Siemens has released a new version for SIMATIC WinCC Unified PC Runtime V21 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.

The following versions of Siemens WinCC Certificate Manager are affected:

  • SIMATIC WinCC Unified PC Runtime V16 vers:all/* 
  • SIMATIC WinCC Unified PC Runtime V17 vers:all/* 
  • SIMATIC WinCC Unified PC Runtime V18 vers:all/* 
  • SIMATIC WinCC Unified PC Runtime V19 vers:all/* 
  • SIMATIC WinCC Unified PC Runtime V20 vers:all/* 
  • SIMATIC WinCC Unified PC Runtime V21 vers:intdot/<21.0.2
CVSS Vendor Equipment Vulnerabilities
v3 7.1 Siemens Siemens WinCC Certificate Manager Cleartext Storage in a File or on Disk

Background

  • Critical Infrastructure Sectors: Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: Germany

Vulnerabilities

Expand All +

CVE-2026-24349

Insufficient protection of key material in WinCC Certificate Manager that could allow an attacker to extract sensitive information.

View CVE Details


Affected Products

Siemens WinCC Certificate Manager
Vendor:
Siemens
Product Version:
SIMATIC WinCC Unified PC Runtime V16, SIMATIC WinCC Unified PC Runtime V17, SIMATIC WinCC Unified PC Runtime V18, SIMATIC WinCC Unified PC Runtime V19, SIMATIC WinCC Unified PC Runtime V20, SIMATIC WinCC Unified PC Runtime V21
Product Status:
known_affected
Remediations

Mitigation
The affected product may be operated only by personnel qualified for the specific task in accordance with the relevant documentation, in particular its warning notices and safety instructions. Qualified personnel are those who, based on their training and experience, are capable of identifying risks and avoiding potential hazards when working with the affected product.

No fix planned
Currently no fix is planned

Vendor fix
Update to V21 Update 2 or later version
https://support.industry.siemens.com/cs/ww/en/view/109991140/

Relevant CWE: CWE-313 Cleartext Storage in a File or on Disk


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 7.1 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Acknowledgments

  • Siemens ProductCERT reported this vulnerability to CISA.

General Recommendations

As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens’ operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity


Additional Resources

For further inquiries on securi

[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.

This article has been indexed from All CISA Advisories

Read the original article: