The vendor explicitly identifies these products as affected by this CVE.
- Totally Integrated Automation Portal (TIA Portal) V15
- Totally Integrated Automation Portal (TIA Portal) V16
- Totally Integrated Automation Portal (TIA Portal) V17
- Totally Integrated Automation Portal (TIA Portal) V18
- Summary
- Affected products contain a path traversal vulnerability that could allow the creation or overwrite of arbitrary files in the engineering system. If the user is tricked to open a malicious PC system configuration file, an attacker could exploit this vulnerability to achieve arbitrary code execution.
- Remediation
- Update to V16 Update 7 or later version
