The vendor explicitly identifies these products as affected by this CVE.
- PSS CAPE Protection Simulation Platform
- SICAM 230
- SIMATIC Information Server 2019
- SIMATIC PCS neo
- SIMATIC Process Historian 2019 (incl. Process Historian OPC UA Server)
- SIMATIC WinCC OA
- SIMIT Simulation Platform
- SINEC INS
- Summary
- Protocol encryption can be easily broken and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.
- Remediation
- CAPE 14 installations installed from material dated 2020-09-15 or later are not affected, as they contain a fixed version of CodeMeter Runtime
