The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC PCS 7 V8.2 and earlier
- SIMATIC PCS 7 V9.0
- SIMATIC PDM
- SIMATIC STEP 7 V5.X
- SINAMICS STARTER (containing STEP 7 OEM version)
- Summary
- A buffer overflow vulnerability could allow a local attacker to cause a Denial-of-Service situation. The security vulnerability could be exploited by an attacker with local access to the affected systems. Successful exploitation requires user privileges but no user interaction. The vulnerability could allow an attacker to compromise the availability of the system as well as to have access to confidential information.
- Remediation
- See recommendations from section Workarounds and Mitigations or upgrade to a newer SIMATIC PCS 7 version
