Siemens UMC Stack (Update H)
The Siemens UMC (Update Management Component) stack contains two security vulnerabilities affecting multiple Siemens industrial software products used on engineering workstations. The vulnerabilities could allow a user with administrative privileges on an engineering workstation to escalate to SYSTEM-level code execution, or trigger a partial denial-of-service condition affecting the UMC component. Affected products include SIMATIC STEP 7 (TIA Portal) versions 15 and 16, SIMOCODE ES, Soft Starter ES, Opcenter suite applications, SIMATIC IT Production Suite, SIMATIC IT LMS, and SIMATIC PCS neo. The vulnerabilities are tracked as CWE-428 (Uncontrolled Resource Consumption), CWE-400 (Uncontrolled Resource Consumption), and CWE-20 (Improper Input Validation).
- Local access to an engineering workstation running affected Siemens software
- Administrator-level user privileges on the workstation
- UMC component must be installed and running
Patching may require device reboot — plan for process interruption
/api/v1/advisories/700c103d-77c5-4fea-9b9a-3f3b8513c78b