The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC NET PC Software V14
- SIMATIC NET PC Software V15
- SIMATIC PCS 7 V8.2
- SIMATIC PCS 7 V9.0
- SIMATIC PCS 7 V9.1
- SIMATIC WinCC
- SINAUT Software ST7sc
- Summary
- Before SIMATIC WinCC V8, legacy OPC services (OPC DA (Data Access), OPC HDA (Historical Data Access), and OPC AE (Alarms & Events)) were used per default. These services were designed on top of the Windows ActiveX and DCOM mechanisms and do not implement state-of-the-art security mechanisms for authentication and encryption of contents.
- Remediation
- Update to V8.0 or later version
