Siemens has an update available to handle an argument injection vulnerability in its SIMATIC WinCC OA Ultralight Client, according to a report with CISA.

 Successful exploitation of this remotely exploitable vulnerability, which Siemens self-reported, could allow an authenticated remote attacker to inject arbitrary parameters when starting the Ultralight Client via the web interface.

The following versions of Siemens SIMATIC WinCC OA, a human machine interface (HMI), suffer from the issue:

  • SIMATIC WinCC OA V3.15: All versions
  • SIMATIC WinCC OA V3.16: All versions prior to V3.16 P035
  • SIMATIC WinCC OA V3.17: All versions prior to V3.17 P024
  • SIMATIC WinCC OA V3.18: All versions prior to V3.18 P014

In the vulnerability, the affected component allows injection of custom arguments into the Ultralight Client backend application under certain circumstances. This could allow an authenticated remote attacker to inject arbitrary parameters when starting the client via the web interface (e.g., open attacker chosen panels with the attacker’s credentials or start a Ctrl script).

Schneider Bold

CVE-2022-44731 is the case number assigned to this vulnerability, which has as a CVSS v3 base score of 5.4.

The product sees use mainly in the critical manufacturing sector, and on a global basis.

No known public exploits specifically target this vulnerability. However, an attacker with low skill level could leverage this low complexity vulnerability.

Siemens released updates for several affected products and recommends updating to the latest versions. Siemens is preparing further updates and recommends specific countermeasures for products where updates are not, or not yet, available.

Siemens identified the following specific workarounds and mitigations users can apply to reduce risk: Configure user permissions and access management according to the WinCC OA Security Guideline.

As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens’ operational guidelines for industrial security and to follow the recommendations in the product manuals.

For more information, click on Siemens security advisory SSA-547714.

ISSSource

Pin It on Pinterest

Share This