The vendor explicitly identifies these products as affected by this CVE.
- Opcenter Quality
- Opcenter RDnL
- SIMATIC PCS neo V4.0
- SIMATIC PCS neo V4.1
- SIMATIC PCS neo V5.0
- SINEC NMS
- SINEMA Remote Connect Client
- Totally Integrated Automation Portal (TIA Portal) V16
- Totally Integrated Automation Portal (TIA Portal) V17
- Totally Integrated Automation Portal (TIA Portal) V18
- Totally Integrated Automation Portal (TIA Portal) V19
- Summary
- Affected products contain a heap-based buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to execute arbitrary code.
- Remediation
- Update to V17 Update 8 or later version
