{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-35783","assignerOrgId":"cec7a2ec-15b4-4faf-bd53-b40f371f3a77","state":"PUBLISHED","assignerShortName":"siemens","dateReserved":"2024-05-17T11:07:53.264Z","datePublished":"2024-09-10T09:36:32.225Z","dateUpdated":"2025-01-14T10:30:01.253Z"},"containers":{"cna":{"providerMetadata":{"orgId":"cec7a2ec-15b4-4faf-bd53-b40f371f3a77","shortName":"siemens","dateUpdated":"2025-01-14T10:30:01.253Z"},"descriptions":[{"lang":"en","value":"A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server 2022 (All versions < V2022 SP1 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC06), SIMATIC Process Historian 2020 (All versions < V2020 SP2 Update 5), SIMATIC Process Historian 2022 (All versions < V2022 SP1 Update 2), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 5), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 3), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 18), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5). The affected products run their DB server with elevated privileges which could allow an authenticated attacker to execute arbitrary OS commands with administrative privileges."}],"affected":[{"vendor":"Siemens","product":"SIMATIC BATCH V9.1","versions":[{"status":"affected","version":"0","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC Information Server 2020","versions":[{"status":"affected","version":"0","lessThan":"V2020 SP2 Update 5","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC Information Server 2022","versions":[{"status":"affected","version":"0","lessThan":"V2022 SP1 Update 2","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC PCS 7 V9.1","versions":[{"status":"affected","version":"0","lessThan":"V9.1 SP2 UC06","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC Process Historian 2020","versions":[{"status":"affected","version":"0","lessThan":"V2020 SP2 Update 5","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC Process Historian 2022","versions":[{"status":"affected","version":"0","lessThan":"V2022 SP1 Update 2","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC WinCC Runtime Professional V18","versions":[{"status":"affected","version":"0","lessThan":"V18 Update 5","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC WinCC Runtime Professional V19","versions":[{"status":"affected","version":"0","lessThan":"V19 Update 3","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC WinCC V7.4","versions":[{"status":"affected","version":"0","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC WinCC V7.5","versions":[{"status":"affected","version":"0","lessThan":"V7.5 SP2 Update 18","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC WinCC V8.0","versions":[{"status":"affected","version":"0","lessThan":"V8.0 Update 5","versionType":"custom"}],"defaultStatus":"unknown"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C","baseScore":9.1,"baseSeverity":"CRITICAL"}},{"cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","baseScore":9.4,"baseSeverity":"CRITICAL"}}],"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-250","description":"CWE-250: Execution with Unnecessary Privileges","type":"CWE"}]}],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-629254.html"}]},"adp":[{"affected":[{"vendor":"siemens","product":"simatic_batch","cpes":["cpe:2.3:a:siemens:simatic_wincc_runtime_professional:18:*:*:*:*:*:*:*","cpe:2.3:a:siemens:simatic_wincc_runtime_professional:19:*:*:*:*:*:*:*","cpe:2.3:h:siemens:simatic_process_historian:2020:-:*:*:*:*:*:*","cpe:2.3:a:siemens:simatic_process_historian:2022:*:*:*:*:*:*:*","cpe:2.3:a:siemens:simatic_pcs7:*:*:*:*:*:*:*:*","cpe:2.3:a:siemens:simatic_information_server:2020:-:*:*:*:*:*:*","cpe:2.3:a:siemens:simatic_information_server:2022:*:*:*:*:*:*:*","cpe:2.3:a:siemens:simatic_batch:9.1:-:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"*","versionType":"custom"}]},{"vendor":"siemens","product":"simatic_wincc","cpes":["cpe:2.3:a:siemens:simatic_wincc:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"7.4","status":"affected","lessThan":"7.5_sp2_update_18","versionType":"custom"},{"version":"8.0","status":"affected","lessThan":"8.0_update_5","versionType":"custom"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-09-10T15:12:46.700884Z","id":"CVE-2024-35783","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-10T17:31:08.389Z"}}]}}