← Back to home
ICSA-22-172-06  ·  Published 2022-06-21  ·  View on CISA ICS-CERT ↗

Siemens WinCC OA

CVSS 9.8 CRITICAL

CVEs (1)

Remediations

  • Enable server-side authentication (SSA) or Kerberos authentication for your WinCC OA project
  • Ensure that server-side authentication (SSA) is enabled for your WinCC OA project (which is the default configuration); alternatively enable Kerberos authentication

Affected Vendors

Siemens

Affected Products (3)

Siemens · SIMATIC WinCC OA V3.16 All_versions_in_default_configuration
Siemens · SIMATIC WinCC OA V3.17 All_versions_in_non-default_configuration
Siemens · SIMATIC WinCC OA V3.18 All_versions_in_non-default_configuration

Affected Sectors

Multiple

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more