The vendor explicitly identifies these products as affected by this CVE.
- Opcenter Execution Foundation
- Opcenter Quality
- SIMATIC PCS neo
- SINEC NMS
- Totally Integrated Automation Portal (TIA Portal) V14
- Totally Integrated Automation Portal (TIA Portal) V15.1
- Totally Integrated Automation Portal (TIA Portal) V16
- Totally Integrated Automation Portal (TIA Portal) V17
- Totally Integrated Automation Portal (TIA Portal) V18
- Summary
- When accessing the UMC Web-UI from affected products, UMC uses an overly permissive CORS policy. This could allow an attacker to trick a legitimate user to trigger unwanted behavior.
- Remediation
- Update to V17 Update 8 or later version
