The vendor explicitly identifies these products as affected by this CVE.
- OpenPCS 7 V8.2
- OpenPCS 7 V9.0
- OpenPCS 7 V9.1
- SIMATIC BATCH V8.2
- SIMATIC BATCH V9.0
- SIMATIC BATCH V9.1
- SIMATIC NET PC Software V14
- SIMATIC NET PC Software V15
- SIMATIC NET PC Software V16
- SIMATIC NET PC Software V17
- SIMATIC PCS 7 V8.2
- SIMATIC PCS 7 V9.0
- Summary
- When downloading files, the affected systems do not properly neutralize special elements within the pathname. An attacker could then cause the pathname to resolve to a location outside of the restricted directory on the server and read unexpected critical files.
- Remediation
- Update to V8.2 SP1; then update SIMATIC WinCC to V7.4 SP1 Update 19 or later version to fix CVE-2021-40358 and CVE-2021-40364
