The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC PCS 7 V8.2
- SIMATIC PCS 7 V9.0
- SIMATIC PCS 7 V9.1
- SIMATIC WinCC V15 and earlier
- SIMATIC WinCC V16
- SIMATIC WinCC V17
- SIMATIC WinCC V7.4
- SIMATIC WinCC V7.5
- Summary
- The password hash of a local user account in the remote server could be granted via public API to a user on the affected system. An authenticated attacker could brute force the password hash and use it to login to the server.
- Remediation
- Update to V16 Update 5 or later version
