4.6
CVSSv2

CVE-2022-24287

Published: 20/05/2022 Updated: 14/11/2023
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC06), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1 UC01), SIMATIC WinCC Runtime Professional V16 and previous versions (All versions), SIMATIC WinCC Runtime Professional V17 (All versions < V17 Upd4), SIMATIC WinCC V7.3 (All versions), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 21), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 8). A missing printer configuration on the host could allow an authenticated malicious user to escape the WinCC Kiosk Mode.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

siemens simatic wincc

siemens simatic wincc 7.5

siemens simatic pcs 7 9.1

siemens simatic pcs 7

siemens simatic wincc runtime professional

siemens simatic wincc runtime professional 17

ICS Advisories