Siemens SIMATIC Software Products (Update B)
Multiple SIMATIC software products contain a vulnerability in how they manage configuration metafiles. An attacker with local access to an engineering workstation could modify these files to change device parameters or operational behavior. The affected products are SIMATIC PCS 7, SIMATIC PDM, SIMATIC STEP 7, and SINAMICS STARTER. Siemens has released updates for most products but notes that SIMATIC PCS 7 V8.2 and earlier versions have no fix available. The vulnerability is not remotely exploitable and requires local filesystem access to the engineering workstation.
- Local access to an engineering workstation running affected SIMATIC software
- Write access to configuration files or metafiles on the workstation
- Knowledge of which parameters to modify for intended effect
Patching may require device reboot — plan for process interruption
/api/v1/advisories/b4ee6354-958f-4482-9c20-347d598b742eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.