The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC STEP 7 Safety V16
- SIMATIC STEP 7 Safety V17
- SIMATIC STEP 7 Safety V18
- SIMATIC STEP 7 V16
- SIMATIC STEP 7 V17
- SIMATIC STEP 7 V18
- SIMATIC WinCC Unified V16
- SIMATIC WinCC Unified V17
- SIMATIC WinCC Unified V18
- SIMATIC WinCC V16
- SIMATIC WinCC V17
- SIMATIC WinCC V18
- Summary
- Affected applications do not properly restrict the .NET BinaryFormatter when deserializing hardware configuration profiles. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected application. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300.
- Remediation
- Update to V16.7 or later version
