ICSA-18-018-01A Siemens SIMATIC WinCC Add-On (Update A)
Multiple SIMATIC WinCC Add-on modules are vulnerable to buffer overflow in the License Manager component. The vulnerability exists in modules including Historian CONNECT ALARM, PI CONNECT series, and the PM-series (PM-AGENT, PM-ANALYZE, PM-CONTROL, PM-MAINT, and PM-OPEN variants), as well as SICEMENT and SIPAPER IT MIS modules. A remote attacker can send a malformed packet to trigger a buffer overflow and execute arbitrary code with application privileges. The License Manager service typically listens on port 4410. Affected versions include all instances of the listed modules up to the specified version numbers. Siemens has not provided firmware patches for these products but recommends updating the underlying License Manager software.
- Network access to WinCC License Manager service (typically port 4410)
- No authentication required
- Affected WinCC Add-on versions must be installed and active
/api/v1/advisories/9a17c48c-5817-4f52-aad8-fc90934bc57aGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.