Siemens SIMATIC WinCC
A vulnerability in SIMATIC WinCC allows authenticated attackers with local access to escape Kiosk Mode, which is a restricted operating mode designed to limit user capabilities on HMI workstations. The vulnerability affects SIMATIC PCS 7 versions 8.2, 9.0, and 9.1; SIMATIC WinCC Runtime Professional versions 16 and 17; and SIMATIC WinCC versions 7.3, 7.4, and 7.5. Kiosk Mode escape could allow an attacker to access the full WinCC interface, potentially enabling unauthorized control of connected industrial processes.
- Local or console access to the WinCC HMI workstation
- Valid user credentials to log into the system (may be default or low-privilege operator account)
- WinCC running in Kiosk Mode
Patching may require device reboot — plan for process interruption
/api/v1/advisories/ef2a7235-78ad-4e85-9394-0051d082f8fbGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.