The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC BATCH V9.1
- SIMATIC Information Server 2020
- SIMATIC Information Server 2022
- SIMATIC PCS 7 V9.1
- SIMATIC Process Historian 2020
- SIMATIC Process Historian 2022
- SIMATIC WinCC Runtime Professional V18
- SIMATIC WinCC Runtime Professional V19
- SIMATIC WinCC V7.4
- SIMATIC WinCC V7.5
- SIMATIC WinCC V8.0
- Summary
- The affected products run their DB server with elevated privileges which could allow an authenticated attacker to execute arbitrary OS commands with administrative privileges.
- Remediation
- Update to V18 Update 5 or later version
