Status: UPDATED
| Advisory ID: CVE-2026-24349
Key Details
| CVE | CVE-2026-24349 |
| CVSS Score / Version | 7.1 (High) / CVSS v3.1 |
| Updated | 2026-07-23 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is none; availability impact is none. |
| Affected products | see table below |
| Classified as | CWE-313 (Cleartext Storage in a File or on Disk) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC Runtime V20 (All versions), SIMATIC WinCC Unified PC Runtime V21 (All versions < V21 Update 2). Insufficient protection of key material in WinCC Certificate Manager that could allow an attacker to extract sensitive information. (NVD)
What to Do
Monitor Siemens's web page for any future patch releases. See vendor advisory link below.
References