The vendor explicitly identifies these products as affected by this CVE.
- OpenPCS 7 V7.1 and earlier
- OpenPCS 7 V8.0
- OpenPCS 7 V8.1
- OpenPCS 7 V8.2
- OpenPCS 7 V9.0
- SIMATIC BATCH V7.1 and earlier
- SIMATIC BATCH V8.0
- SIMATIC BATCH V8.1
- SIMATIC BATCH V8.2
- SIMATIC BATCH V9.0
- SIMATIC NET PC Software V14
- SIMATIC NET PC Software V15
- Summary
- Specially crafted messages sent to the RPC service of the affected products could cause a Denial-of-Service condition on the remote and local communication functionality of the affected products. A reboot of the system is required to recover the remote and local communication functionality. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.
- Remediation
- Update to OpenPCS 7 V8.1 Upd 5 or later version
