Machine-generated analysis · WAYSCloud LLM
The advisory states that WinCC Certificate Manager stores key material with insufficient protection, potentially allowing extraction of sensitive information.
Context
The affected product is Siemens WinCC Certificate Manager, part of the SIMATIC WinCC Unified PC Runtime. The advisory states that affected versions store key material insecurely, which could allow an attacker to extract sensitive information. This issue affects all versions prior to V21.0.2, including V16 through V20. The advisory notes that Siemens has released a new version to address the issue and recommends updating to the latest version where possible.
Operator considerations
Check: inventory SIMATIC WinCC Unified PC Runtime installations for versions prior to V21.0.2
Patch: update to SIMATIC WinCC Unified PC Runtime V21.0.2 or later if available
Isolate: restrict access to systems running affected versions if patching is not immediately possible
Log: monitor for unauthorized access to certificate-related files on affected systems
WinCC Certificate Manager insufficiently protects key material that could allow an attacker to extract sensitive information. Siemens has released a new version for SIMATIC WinCC Unified PC Runtime V21 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.
The following versions of Siemens WinCC Certificate Manager are affected:
SIMATIC WinCC Unified PC Runtime V16 vers:all/*
SIMATIC WinCC Unified PC Runtime V17 vers:all/*
SIMATIC WinCC Unified PC Runtime V18 vers:all/*
SIMATIC WinCC Unified PC Runtime V19 vers:all/*
SIMATIC WinCC Unified PC Runtime V20 vers:all/*
SIMATIC WinCC Unified PC Runtime V21 vers:intdot/
Read the full advisory on CISA →