ssa-282044
Vulnerability from csaf_siemens
Published
2025-08-12 00:00
Modified
2025-08-12 00:00
Summary
SSA-282044: DLL Hijacking Vulnerability in Siemens Web Installer used by the Online Software Delivery
Notes
Summary
The installers used to install several Siemens products are affected by a DLL hijacking vulnerability. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected installer component. This vulnerability poses a risk only during setup and installation phase of the affected applications downloaded e.g. via OSD (Online Software Delivery).
Siemens has released new versions for several affected products and recommends using the latest versions during setup and installation. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
General Recommendations
As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download:
https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.
Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity
Additional Resources
For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories
Terms of Use
The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.
{ "document": { "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Disclosure is not limited. (TLPv2: TLP:CLEAR)", "tlp": { "label": "WHITE" } }, "lang": "en", "notes": [ { "category": "summary", "text": "The installers used to install several Siemens products are affected by a DLL hijacking vulnerability. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected installer component. This vulnerability poses a risk only during setup and installation phase of the affected applications downloaded e.g. via OSD (Online Software Delivery).\n\nSiemens has released new versions for several affected products and recommends using the latest versions during setup and installation. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.", "title": "Summary" }, { "category": "general", "text": "As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens\u0027 operational guidelines for Industrial Security (Download: \nhttps://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.\nAdditional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity", "title": "General Recommendations" }, { "category": "general", "text": "For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories", "title": "Additional Resources" }, { "category": "legal_disclaimer", "text": "The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.", "title": "Terms of Use" } ], "publisher": { "category": "vendor", "contact_details": "productcert@siemens.com", "name": "Siemens ProductCERT", "namespace": "https://www.siemens.com" }, "references": [ { "category": "self", "summary": "SSA-282044: DLL Hijacking Vulnerability in Siemens Web Installer used by the Online Software Delivery - HTML Version", "url": "https://cert-portal.siemens.com/productcert/html/ssa-282044.html" }, { "category": "self", "summary": "SSA-282044: DLL Hijacking Vulnerability in Siemens Web Installer used by the Online Software Delivery - CSAF Version", "url": "https://cert-portal.siemens.com/productcert/csaf/ssa-282044.json" } ], "title": "SSA-282044: DLL Hijacking Vulnerability in Siemens Web Installer used by the Online Software Delivery", "tracking": { "current_release_date": "2025-08-12T00:00:00Z", "generator": { "engine": { "name": "Siemens ProductCERT CSAF Generator", "version": "1" } }, "id": "SSA-282044", "initial_release_date": "2025-08-12T00:00:00Z", "revision_history": [ { "date": "2025-08-12T00:00:00Z", "legacy_version": "1.0", "number": "1", "summary": "Publication Date" } ], "status": "interim", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "Automation License Manager V6.0", "product_id": "1" } } ], "category": "product_name", "name": "Automation License Manager V6.0" }, { "branches": [ { "category": "product_version_range", "name": "All versions \u003c V6.2 Upd3", "product": { "name": "Automation License Manager V6.2", "product_id": "2" } } ], "category": "product_name", "name": "Automation License Manager V6.2" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "CEMAT V10.0", "product_id": "3" } } ], "category": "product_name", "name": "CEMAT V10.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "CP PtP Param configuring interface", "product_id": "4" } } ], "category": "product_name", "name": "CP PtP Param configuring interface" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "Create MyConfig (CMC)", "product_id": "5" } } ], "category": "product_name", "name": "Create MyConfig (CMC)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "Energy Support Library (EnSL)", "product_id": "6" } } ], "category": "product_name", "name": "Energy Support Library (EnSL)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "FM Configuration Package", "product_id": "7" } } ], "category": "product_name", "name": "FM Configuration Package" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "Modular PID CTRL Tool", "product_id": "8" } } ], "category": "product_name", "name": "Modular PID CTRL Tool" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "MultiFieldbus Configuration Tool\u00a0(MFCT)", "product_id": "9" } } ], "category": "product_name", "name": "MultiFieldbus Configuration Tool\u00a0(MFCT)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "OpenPCS 7 V9.1", "product_id": "10" } } ], "category": "product_name", "name": "OpenPCS 7 V9.1" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "OpenPCS 7 V10.0", "product_id": "11" } } ], "category": "product_name", "name": "OpenPCS 7 V10.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "Siemens Network Planner (SINETPLAN)", "product_id": "12" } } ], "category": "product_name", "name": "Siemens Network Planner (SINETPLAN)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Automation Tool", "product_id": "13" } } ], "category": "product_name", "name": "SIMATIC Automation Tool" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Automation Tool SDK Windows", "product_id": "14" } } ], "category": "product_name", "name": "SIMATIC Automation Tool SDK Windows" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC BATCH V9.1", "product_id": "15" } } ], "category": "product_name", "name": "SIMATIC BATCH V9.1" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC BATCH V10.0", "product_id": "16" } } ], "category": "product_name", "name": "SIMATIC BATCH V10.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Control Function Library (CFL) V1.0.0", "product_id": "17" } } ], "category": "product_name", "name": "SIMATIC Control Function Library (CFL) V1.0.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Control Function Library (CFL) V2.0", "product_id": "18" } } ], "category": "product_name", "name": "SIMATIC Control Function Library (CFL) V2.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Control Function Library (CFL) V3.0", "product_id": "19" } } ], "category": "product_name", "name": "SIMATIC Control Function Library (CFL) V3.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Control Function Library (CFL) V4.0", "product_id": "20" } } ], "category": "product_name", "name": "SIMATIC Control Function Library (CFL) V4.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC eaSie Core Package (6DL5424-0AX00-0AV8)", "product_id": "21", "product_identification_helper": { "model_numbers": [ "6DL5424-0AX00-0AV8" ] } } } ], "category": "product_name", "name": "SIMATIC eaSie Core Package (6DL5424-0AX00-0AV8)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC eaSie Document Skills", "product_id": "22" } } ], "category": "product_name", "name": "SIMATIC eaSie Document Skills" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC eaSie PCS 7 Skill Package (6DL5424-0BX00-0AV8)", "product_id": "23", "product_identification_helper": { "model_numbers": [ "6DL5424-0BX00-0AV8" ] } } } ], "category": "product_name", "name": "SIMATIC eaSie PCS 7 Skill Package (6DL5424-0BX00-0AV8)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC eaSie Workflow Skills", "product_id": "24" } } ], "category": "product_name", "name": "SIMATIC eaSie Workflow Skills" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Energy Suite V17", "product_id": "25" } } ], "category": "product_name", "name": "SIMATIC Energy Suite V17" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Energy Suite V18", "product_id": "26" } } ], "category": "product_name", "name": "SIMATIC Energy Suite V18" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Energy Suite V19", "product_id": "27" } } ], "category": "product_name", "name": "SIMATIC Energy Suite V19" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Logon V1.6", "product_id": "28" } } ], "category": "product_name", "name": "SIMATIC Logon V1.6" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Logon V2.0", "product_id": "29" } } ], "category": "product_name", "name": "SIMATIC Logon V2.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Management Agent", "product_id": "30" } } ], "category": "product_name", "name": "SIMATIC Management Agent" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Management Console", "product_id": "31" } } ], "category": "product_name", "name": "SIMATIC Management Console" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC MTP CREATOR V3.x", "product_id": "32" } } ], "category": "product_name", "name": "SIMATIC MTP CREATOR V3.x" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC MTP CREATOR V4.x", "product_id": "33" } } ], "category": "product_name", "name": "SIMATIC MTP CREATOR V4.x" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC MTP CREATOR\u00a0V2.x", "product_id": "34" } } ], "category": "product_name", "name": "SIMATIC MTP CREATOR\u00a0V2.x" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC MTP CREATOR\u00a0V5.x", "product_id": "35" } } ], "category": "product_name", "name": "SIMATIC MTP CREATOR\u00a0V5.x" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC MTP Integrator V1.x", "product_id": "36" } } ], "category": "product_name", "name": "SIMATIC MTP Integrator V1.x" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC MTP Integrator V2.x", "product_id": "37" } } ], "category": "product_name", "name": "SIMATIC MTP Integrator V2.x" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC NET PC Software V16", "product_id": "38" } } ], "category": "product_name", "name": "SIMATIC NET PC Software V16" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC NET PC Software V17", "product_id": "39" } } ], "category": "product_name", "name": "SIMATIC NET PC Software V17" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC NET PC Software V18", "product_id": "40" } } ], "category": "product_name", "name": "SIMATIC NET PC Software V18" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC NET PC Software V19", "product_id": "41" } } ], "category": "product_name", "name": "SIMATIC NET PC Software V19" }, { "branches": [ { "category": "product_version_range", "name": "All versions \u003c V20.0 Update 1", "product": { "name": "SIMATIC NET PC Software V20", "product_id": "42" } } ], "category": "product_name", "name": "SIMATIC NET PC Software V20" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC ODK 1500S", "product_id": "43" } } ], "category": "product_name", "name": "SIMATIC ODK 1500S" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Advanced Process Faceplates V9.1", "product_id": "44" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Advanced Process Faceplates V9.1" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Advanced Process Functions V2.1", "product_id": "45" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Advanced Process Functions V2.1" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Advanced Process Functions V2.2", "product_id": "46" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Advanced Process Functions V2.2" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Advanced Process Graphics V9.1", "product_id": "47" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Advanced Process Graphics V9.1" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Advanced Process Graphics V10.0", "product_id": "48" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Advanced Process Graphics V10.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Advanced Process Library incl. Faceplates V10.0", "product_id": "49" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Advanced Process Library incl. Faceplates V10.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Advanced Process Library V9.1", "product_id": "50" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Advanced Process Library V9.1" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Basis Faceplates V9.1", "product_id": "51" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Basis Faceplates V9.1" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Basis Library V9.1", "product_id": "52" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Basis Library V9.1" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Basis Library V10.0", "product_id": "53" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Basis Library V10.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Industry Library V9.0", "product_id": "54" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Industry Library V9.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Industry Library V9.1", "product_id": "55" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Industry Library V9.1" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Industry Library V10.0", "product_id": "56" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Industry Library V10.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Logic Matrix V9.1", "product_id": "57" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Logic Matrix V9.1" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Logic Matrix V10.0", "product_id": "58" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Logic Matrix V10.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 MPC Configurator", "product_id": "59" } } ], "category": "product_name", "name": "SIMATIC PCS 7 MPC Configurator" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 PowerControl", "product_id": "60" } } ], "category": "product_name", "name": "SIMATIC PCS 7 PowerControl" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Standard Chemical Library V9.1", "product_id": "61" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Standard Chemical Library V9.1" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 Standard Chemical Library V10.0", "product_id": "62" } } ], "category": "product_name", "name": "SIMATIC PCS 7 Standard Chemical Library V10.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 TeleControl", "product_id": "63" } } ], "category": "product_name", "name": "SIMATIC PCS 7 TeleControl" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 V9.1", "product_id": "64" } } ], "category": "product_name", "name": "SIMATIC PCS 7 V9.1" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7 V10.0", "product_id": "65" } } ], "category": "product_name", "name": "SIMATIC PCS 7 V10.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS 7/OPEN OS V9.1", "product_id": "66" } } ], "category": "product_name", "name": "SIMATIC PCS 7/OPEN OS V9.1" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PCS neo V5.0", "product_id": "67" } } ], "category": "product_name", "name": "SIMATIC PCS neo V5.0" }, { "branches": [ { "category": "product_version_range", "name": "All versions \u003c V6.0 SP1", "product": { "name": "SIMATIC PCS neo V6.0", "product_id": "68" } } ], "category": "product_name", "name": "SIMATIC PCS neo V6.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PDM Maintenance Station V5.0", "product_id": "69" } } ], "category": "product_name", "name": "SIMATIC PDM Maintenance Station V5.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PDM V9.2", "product_id": "70" } } ], "category": "product_name", "name": "SIMATIC PDM V9.2" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC PDM V9.3", "product_id": "71" } } ], "category": "product_name", "name": "SIMATIC PDM V9.3" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Process Function Library (PFL) V4.0", "product_id": "72" } } ], "category": "product_name", "name": "SIMATIC Process Function Library (PFL) V4.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Process Historian 2020", "product_id": "73" } } ], "category": "product_name", "name": "SIMATIC Process Historian 2020" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Process Historian 2022", "product_id": "74" } } ], "category": "product_name", "name": "SIMATIC Process Historian 2022" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Process Historian 2024", "product_id": "75" } } ], "category": "product_name", "name": "SIMATIC Process Historian 2024" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC ProSave V17", "product_id": "76" } } ], "category": "product_name", "name": "SIMATIC ProSave V17" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC ProSave V18", "product_id": "77" } } ], "category": "product_name", "name": "SIMATIC ProSave V18" }, { "branches": [ { "category": "product_version_range", "name": "All versions \u003c V19 Update 4", "product": { "name": "SIMATIC ProSave V19", "product_id": "78" } } ], "category": "product_name", "name": "SIMATIC ProSave V19" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC ProSave V20", "product_id": "79" } } ], "category": "product_name", "name": "SIMATIC ProSave V20" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Route Control V9.1", "product_id": "80" } } ], "category": "product_name", "name": "SIMATIC Route Control V9.1" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Route Control V10.0", "product_id": "81" } } ], "category": "product_name", "name": "SIMATIC Route Control V10.0" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC S7 F Systems V6.3", "product_id": "82" } } ], "category": "product_name", "name": "SIMATIC S7 F Systems V6.3" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC S7 F Systems V6.4", "product_id": "83" } } ], "category": "product_name", "name": "SIMATIC S7 F Systems V6.4" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC S7-1500 Software Controller V2", "product_id": "84" } } ], "category": "product_name", "name": "SIMATIC S7-1500 Software Controller V2" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC S7-1500 Software Controller V3", "product_id": "85" } } ], "category": "product_name", "name": "SIMATIC S7-1500 Software Controller V3" }, { "branches": [ { "category": "product_version_range", "name": "vers:intdot/\u003c4.0.1", "product": { "name": "SIMATIC S7-Fail-safe Configuration Tool (S7-FCT)", "product_id": "86" } } ], "category": "product_name", "name": "SIMATIC S7-Fail-safe Configuration Tool (S7-FCT)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC S7-PCT", "product_id": "87" } } ], "category": "product_name", "name": "SIMATIC S7-PCT" }, { "branches": [ { "category": "product_version_range", "name": "All versions \u003c V7.0 Update 1", "product": { "name": "SIMATIC S7-PLCSIM Advanced", "product_id": "88" } } ], "category": "product_name", "name": "SIMATIC S7-PLCSIM Advanced" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC S7-PLCSIM V17", "product_id": "89" } } ], "category": "product_name", "name": "SIMATIC S7-PLCSIM V17" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC S7-PLCSIM V18", "product_id": "90" } } ], "category": "product_name", "name": "SIMATIC S7-PLCSIM V18" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC S7-PLCSIM V19", "product_id": "91" } } ], "category": "product_name", "name": "SIMATIC S7-PLCSIM V19" }, { "branches": [ { "category": "product_version_range", "name": "All versions \u003c V20 Update 1", "product": { "name": "SIMATIC S7-PLCSIM V20", "product_id": "92" } } ], "category": "product_name", "name": "SIMATIC S7-PLCSIM V20" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Safety Matrix", "product_id": "93" } } ], "category": "product_name", "name": "SIMATIC Safety Matrix" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC STEP 7 CFC V19", "product_id": "94" } } ], "category": "product_name", "name": "SIMATIC STEP 7 CFC V19" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC STEP 7 CFC V20", "product_id": "95" } } ], "category": "product_name", "name": "SIMATIC STEP 7 CFC V20" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC STEP 7 V5.7", "product_id": "96" } } ], "category": "product_name", "name": "SIMATIC STEP 7 V5.7" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC Target", "product_id": "97" } } ], "category": "product_name", "name": "SIMATIC Target" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC WinCC flexible ES", "product_id": "98" } } ], "category": "product_name", "name": "SIMATIC WinCC flexible ES" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC WinCC Runtime Advanced", "product_id": "99" } } ], "category": "product_name", "name": "SIMATIC WinCC Runtime Advanced" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC WinCC Runtime Professional", "product_id": "100" } } ], "category": "product_name", "name": "SIMATIC WinCC Runtime Professional" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC WinCC Runtime Professional V20", "product_id": "101" } } ], "category": "product_name", "name": "SIMATIC WinCC Runtime Professional V20" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC WinCC TeleControl", "product_id": "102" } } ], "category": "product_name", "name": "SIMATIC WinCC TeleControl" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC WinCC Unified Line Coordination", "product_id": "103" } } ], "category": "product_name", "name": "SIMATIC WinCC Unified Line Coordination" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC WinCC Unified PC Runtime V18", "product_id": "104" } } ], "category": "product_name", "name": "SIMATIC WinCC Unified PC Runtime V18" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC WinCC Unified PC Runtime V19", "product_id": "105" } } ], "category": "product_name", "name": "SIMATIC WinCC Unified PC Runtime V19" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC WinCC Unified PC Runtime V20", "product_id": "106" } } ], "category": "product_name", "name": "SIMATIC WinCC Unified PC Runtime V20" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC WinCC Unified Sequence", "product_id": "107" } } ], "category": "product_name", "name": "SIMATIC WinCC Unified Sequence" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC WinCC V7.5", "product_id": "108" } } ], "category": "product_name", "name": "SIMATIC WinCC V7.5" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC WinCC V8.0", "product_id": "109" } } ], "category": "product_name", "name": "SIMATIC WinCC V8.0" }, { "branches": [ { "category": "product_version_range", "name": "All versions \u003c V8.1 Update 3", "product": { "name": "SIMATIC WinCC V8.1", "product_id": "110" } } ], "category": "product_name", "name": "SIMATIC WinCC V8.1" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC WinCC Visualization Architect (SiVArc) V17", "product_id": "111" } } ], "category": "product_name", "name": "SIMATIC WinCC Visualization Architect (SiVArc) V17" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC WinCC Visualization Architect (SiVArc) V18", "product_id": "112" } } ], "category": "product_name", "name": "SIMATIC WinCC Visualization Architect (SiVArc) V18" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC WinCC Visualization Architect (SiVArc) V19", "product_id": "113" } } ], "category": "product_name", "name": "SIMATIC WinCC Visualization Architect (SiVArc) V19" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC WinCC Visualization Architect (SiVArc) V20", "product_id": "114" } } ], "category": "product_name", "name": "SIMATIC WinCC Visualization Architect (SiVArc) V20" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMATIC\u00a0D7-SYS", "product_id": "115" } } ], "category": "product_name", "name": "SIMATIC\u00a0D7-SYS" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMIT Rapid Tester", "product_id": "116" } } ], "category": "product_name", "name": "SIMIT Rapid Tester" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SIMIT Simulation Platform", "product_id": "117" } } ], "category": "product_name", "name": "SIMIT Simulation Platform" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SINAMICS Startdrive V17", "product_id": "118" } } ], "category": "product_name", "name": "SINAMICS Startdrive V17" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SINAMICS Startdrive V18", "product_id": "119" } } ], "category": "product_name", "name": "SINAMICS Startdrive V18" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SINAMICS Startdrive V19", "product_id": "120" } } ], "category": "product_name", "name": "SINAMICS Startdrive V19" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SINAMICS Startdrive V20", "product_id": "121" } } ], "category": "product_name", "name": "SINAMICS Startdrive V20" }, { "branches": [ { "category": "product_version_range", "name": "vers:intdot/\u003c4.0", "product": { "name": "SINEC NMS", "product_id": "122" } } ], "category": "product_name", "name": "SINEC NMS" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SINEMA Remote Connect Client", "product_id": "123" } } ], "category": "product_name", "name": "SINEMA Remote Connect Client" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "SITRANS", "product_id": "124" } } ], "category": "product_name", "name": "SITRANS" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "Standard PID CTRL Tool", "product_id": "125" } } ], "category": "product_name", "name": "Standard PID CTRL Tool" }, { "branches": [ { "category": "product_version_range", "name": "vers:intdot/\u003c3.1.2.2", "product": { "name": "TeleControl Server Basic V3.1", "product_id": "126" } } ], "category": "product_name", "name": "TeleControl Server Basic V3.1" }, { "branches": [ { "category": "product_version_range", "name": "vers:intdot/\u003c3.0.6", "product": { "name": "TIA Administrator", "product_id": "127" } } ], "category": "product_name", "name": "TIA Administrator" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "TIA Portal Cloud Connector", "product_id": "128" } } ], "category": "product_name", "name": "TIA Portal Cloud Connector" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "TIA Portal Test Suite V17", "product_id": "129" } } ], "category": "product_name", "name": "TIA Portal Test Suite V17" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "TIA Portal Test Suite V18", "product_id": "130" } } ], "category": "product_name", "name": "TIA Portal Test Suite V18" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "TIA Portal Test Suite V19", "product_id": "131" } } ], "category": "product_name", "name": "TIA Portal Test Suite V19" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "TIA Portal Test Suite V20", "product_id": "132" } } ], "category": "product_name", "name": "TIA Portal Test Suite V20" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "TIA Project-Server", "product_id": "133" } } ], "category": "product_name", "name": "TIA Project-Server" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "TIA Project-Server V17", "product_id": "134" } } ], "category": "product_name", "name": "TIA Project-Server V17" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "WinCC Panel Image Setup", "product_id": "135" } } ], "category": "product_name", "name": "WinCC Panel Image Setup" } ], "category": "vendor", "name": "Siemens" } ] }, "vulnerabilities": [ { "cve": "CVE-2025-30033", "cwe": { "id": "CWE-427", "name": "Uncontrolled Search Path Element" }, "notes": [ { "category": "summary", "text": "The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5", "6", "7", "8", "9", "10", "11", "12", "13", "14", "15", "16", "17", "18", "19", "20", "21", "22", "23", "24", "25", "26", "27", "28", "29", "30", "31", "32", "33", "34", "35", "36", "37", "38", "39", "40", "41", "42", "43", "44", "45", "46", "47", "48", "49", "50", "51", "52", "53", "54", "55", "56", "57", "58", "59", "60", "61", "62", "63", "64", "65", "66", "67", "68", "69", "70", "71", "72", "73", "74", "75", "76", "77", "78", "79", "80", "81", "82", "83", "84", "85", "86", "87", "88", "89", "90", "91", "92", "93", "94", "95", "96", "97", "98", "99", "100", "101", "102", "103", "104", "105", "106", "107", "108", "109", "110", "111", "112", "113", "114", "115", "116", "117", "118", "119", "120", "121", "122", "123", "124", "125", "126", "127", "128", "129", "130", "131", "132", "133", "134", "135" ] }, "remediations": [ { "category": "mitigation", "details": "Harden the application host to prevent local access by untrusted personnel", "product_ids": [ "1", "2", "3", "4", "5", "6", "7", "8", "9", "10", "11", "12", "13", "14", "15", "16", "17", "18", "19", "20", "21", "22", "23", "24", "25", "26", "27", "28", "29", "30", "31", "32", "33", "34", "35", "36", "37", "38", "39", "40", "41", "42", "43", "44", "45", "46", "47", "48", "49", "50", "51", "52", "53", "54", "55", "56", "57", "58", "59", "60", "61", "62", "63", "64", "65", "66", "67", "68", "69", "70", "71", "72", "73", "74", "75", "76", "77", "78", "79", "80", "81", "82", "83", "84", "85", "86", "87", "88", "89", "90", "91", "92", "93", "94", "95", "96", "97", "98", "99", "100", "101", "102", "103", "104", "105", "106", "107", "108", "109", "110", "111", "112", "113", "114", "115", "116", "117", "118", "119", "120", "121", "122", "123", "124", "125", "126", "127", "128", "129", "130", "131", "132", "133", "134", "135" ] }, { "category": "mitigation", "details": "Install applications only from an empty directory, thereby minimizing the likelihood of malicious DLLs being present", "product_ids": [ "1", "2", "3", "4", "5", "6", "7", "8", "9", "10", "11", "12", "13", "14", "15", "16", "17", "18", "19", "20", "21", "22", "23", "24", "25", "26", "27", "28", "29", "30", "31", "32", "33", "34", "35", "36", "37", "38", "39", "40", "41", "42", "43", "44", "45", "46", "47", "48", "49", "50", "51", "52", "53", "54", "55", "56", "57", "58", "59", "60", "61", "62", "63", "64", "65", "66", "67", "68", "69", "70", "71", "72", "73", "74", "75", "76", "77", "78", "79", "80", "81", "82", "83", "84", "85", "86", "87", "88", "89", "90", "91", "92", "93", "94", "95", "96", "97", "98", "99", "100", "101", "102", "103", "104", "105", "106", "107", "108", "109", "110", "111", "112", "113", "114", "115", "116", "117", "118", "119", "120", "121", "122", "123", "124", "125", "126", "127", "128", "129", "130", "131", "132", "133", "134", "135" ] }, { "category": "no_fix_planned", "details": "Currently no fix is planned", "product_ids": [ "1", "3", "6", "15", "28", "32", "34", "54", "67", "72", "73", "77", "82", "94", "95" ] }, { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "4", "5", "7", "8", "9", "10", "11", "12", "13", "14", "16", "17", "18", "19", "20", "21", "22", "23", "24", "25", "26", "27", "29", "30", "31", "33", "35", "36", "37", "38", "39", "40", "41", "43", "44", "45", "46", "47", "48", "49", "50", "51", "52", "53", "55", "56", "57", "58", "59", "60", "61", "62", "63", "64", "65", "66", "69", "70", "71", "74", "75", "76", "79", "80", "81", "83", "84", "85", "87", "89", "90", "91", "93", "96", "97", "98", "99", "100", "101", "102", "103", "104", "105", "106", "107", "108", "109", "111", "112", "113", "114", "115", "116", "117", "118", "119", "120", "121", "123", "124", "125", "128", "129", "130", "131", "132", "133", "134", "135" ] }, { "category": "vendor_fix", "details": "Update to V19 Update 4 or later version", "product_ids": [ "78" ] }, { "category": "vendor_fix", "details": "Update to V20 Update 1 or later version", "product_ids": [ "92" ], "url": "https://support.industry.siemens.com/cs/ww/en/view/109963851/" }, { "category": "vendor_fix", "details": "Update to V20.0 Update 1 or later version", "product_ids": [ "42" ], "url": "https://support.industry.siemens.com/cs/ww/en/view/109987675/" }, { "category": "vendor_fix", "details": "Update to V3.0.6 or later version", "product_ids": [ "127" ], "url": "https://support.industry.siemens.com/cs/ww/en/view/109825038/" }, { "category": "vendor_fix", "details": "Update to V3.1.2.2 or later version", "product_ids": [ "126" ], "url": "https://support.industry.siemens.com/cs/ww/en/view/109987362/" }, { "category": "vendor_fix", "details": "Update to V4.0 or later version", "product_ids": [ "122" ], "url": "https://support.industry.siemens.com/cs/ww/en/view/109989514/" }, { "category": "vendor_fix", "details": "Update to V4.0.1 or later version", "product_ids": [ "86" ], "url": "https://support.industry.siemens.com/cs/ww/en/view/109762827/" }, { "category": "vendor_fix", "details": "Update to V6.0 SP1 or later version", "product_ids": [ "68" ], "url": "https://support.industry.siemens.com/cs/ww/en/view/109991149/" }, { "category": "vendor_fix", "details": "Update to V6.2 Upd3 or later version", "product_ids": [ "2" ], "url": "https://support.industry.siemens.com/cs/ww/en/view/114358/" }, { "category": "vendor_fix", "details": "Update to V7.0 Update 1 or later version", "product_ids": [ "88" ], "url": "https://support.industry.siemens.com/cs/ww/en/view/109988436/" }, { "category": "vendor_fix", "details": "Update to V8.1 Update 3 or later version", "product_ids": [ "110" ], "url": "https://support.industry.siemens.com/cs/ww/en/view/109977191/" } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5", "6", "7", "8", "9", "10", "11", "12", "13", "14", "15", "16", "17", "18", "19", "20", "21", "22", "23", "24", "25", "26", "27", "28", "29", "30", "31", "32", "33", "34", "35", "36", "37", "38", "39", "40", "41", "42", "43", "44", "45", "46", "47", "48", "49", "50", "51", "52", "53", "54", "55", "56", "57", "58", "59", "60", "61", "62", "63", "64", "65", "66", "67", "68", "69", "70", "71", "72", "73", "74", "75", "76", "77", "78", "79", "80", "81", "82", "83", "84", "85", "86", "87", "88", "89", "90", "91", "92", "93", "94", "95", "96", "97", "98", "99", "100", "101", "102", "103", "104", "105", "106", "107", "108", "109", "110", "111", "112", "113", "114", "115", "116", "117", "118", "119", "120", "121", "122", "123", "124", "125", "126", "127", "128", "129", "130", "131", "132", "133", "134", "135" ] } ], "title": "CVE-2025-30033" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…