The vendor explicitly identifies these products as affected by this CVE.
- OpenPCS 7 V9.1
- SIMATIC NET PC Software V14
- SIMATIC NET PC Software V15
- SIMATIC NET PC Software V16
- SIMATIC NET PC Software V17
- SIMATIC NET PC Software V18
- SIMATIC Process Historian 2020 OPC UA Server
- SIMATIC Process Historian 2022 OPC UA Server
- SIMATIC WinCC
- SIMATIC WinCC Runtime Professional
- SIMATIC WinCC Unified PC Runtime V18
- TeleControl Server Basic V3
- Summary
- OPC Foundation Local Discovery Server (LDS) in affected products uses a hard-coded file path to a configuration file. This allows a normal user to create a malicious file that is loaded by LDS (running as a high-privilege user).
- Remediation
- Update to V16 Update 8 or later version
