The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC PCS neo V4.1
- SIMATIC PCS neo V5.0
- SINEC NMS
- SINEMA Remote Connect
- Totally Integrated Automation Portal (TIA Portal) V17
- Totally Integrated Automation Portal (TIA Portal) V18
- Totally Integrated Automation Portal (TIA Portal) V19
- Totally Integrated Automation Portal (TIA Portal) V20
- User Management Component (UMC)
- Summary
- Affected products contain a out of bound read buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to cause a denial of service condition.
- Remediation
- Update to V2.15.1.1 or later version
