Arbitrary file upload in Siemens products - CVE-2019-10935
Published: July 12, 2019
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file uploads. A remote authenticated user with network access to the WinCC DataMonitor application can upload arbitrary ASPX code on the server.
The vulnerability is relevant only in situations where an attacker has access via the web interface but not to the directory structure.
Affected software
SIMATIC PCS 7
SIMATIC WinCC Runtime Professional
SIMATIC WinCC Professional
How to mitigate CVE-2019-10935
SIMATIC PCS 7 - update to 7.4 SP1 Update 11