← Back to home
SIEMENS-SSA-508677  ·  Published 2023-06-13  ·  View on Siemens ProductCERT ↗

SSA-508677 V1.0: Use of Obsolete Function Vulnerability in SIMATIC WinCC before V8

CVSS N/A MEDIUM

Risk Summary

<p>Before SIMATIC WinCC V8, legacy OPC services (OPC DA (Data Access), OPC HDA (Historical Data Access), and OPC AE (Alarms &amp; Events)) were used per default. These services were designed on top of the Windows ActiveX and DCOM mechanisms and do not implement state-of-the-art security mechanisms for authentication and encryption of contents.</p> <p>Starting with WinCC V8.0 the legacy OPC services are no longer enabled by default in new installations. Siemens recommends to use OPC UA instead and to disable the legacy OPC services. For deployments where the legacy OPC services are still in use, ensure that only trusted users are part of the SIMATIC HMI group.</p>

Remediations

  • Refer to Siemens ProductCERT advisory for patch and remediation guidance.

Affected Vendors

Siemens

Affected Products (1)

Siemens · SSA-508677 V1.0: Use of Obsolete Function Vulnerability in SIMATIC WinCC before V8 See advisory

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more