← All Advisories

CVE-2026-24349

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-24349

Key Details

CVECVE-2026-24349
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-07-23
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productssee table below
Classified asCWE-313 (Cleartext Storage in a File or on Disk)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Siemenssimatic_wincc_unified_pc_runtime
SiemensSIMATIC WinCC Unified PC Runtime V16
SiemensSIMATIC WinCC Unified PC Runtime V17
SiemensSIMATIC WinCC Unified PC Runtime V18
SiemensSIMATIC WinCC Unified PC Runtime V19
SiemensSIMATIC WinCC Unified PC Runtime V20
SiemensSIMATIC WinCC Unified PC Runtime V21
SubsystemsGeneral OT
SectorsMultiple

What to Know

A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC Runtime V20 (All versions), SIMATIC WinCC Unified PC Runtime V21 (All versions < V21 Update 2). Insufficient protection of key material in WinCC Certificate Manager that could allow an attacker to extract sensitive information. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-24349
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-24349
Vendor advisoryhttps://cert-portal.siemens.com/productcert/html/ssa-063511.html