Arbitrary file upload in Siemens products - CVE-2019-10935

 

Arbitrary file upload in Siemens products - CVE-2019-10935

Published: July 12, 2019


Vulnerability identifier: #VU19158
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10935
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file uploads. A remote authenticated user with network access to the WinCC DataMonitor application can upload arbitrary ASPX code on the server.

The vulnerability is relevant only in situations where an attacker has access via the web interface but not to the directory structure.


Affected software

Siemens SIMATIC WinCC
SIMATIC PCS 7
SIMATIC WinCC Runtime Professional
SIMATIC WinCC Professional

How to mitigate CVE-2019-10935

Install updates from vendor's website.

Siemens SIMATIC WinCC - addressed in versions 7.4 Sp1 Update 11, 7.5 Update 3
SIMATIC PCS 7 - update to 7.4 SP1 Update 11

External References

Related Security Bulletins