A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC Runtime V20 (All versions), SIMATIC WinCC Unified PC Runtime V21 (All versions < V21 Update 2). Insufficient protection of key material in WinCC Certificate Manager that could allow an attacker to extract sensitive information.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens simatic Wincc Unified Pc Runtime |
|
| Vendors & Products |
Siemens
Siemens simatic Wincc Unified Pc Runtime |
Tue, 09 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure Storage of Key Material in SIMATIC WinCC Unified PC Runtime |
Tue, 09 Jun 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC Runtime V20 (All versions), SIMATIC WinCC Unified PC Runtime V21 (All versions < V21 Update 2). Insufficient protection of key material in WinCC Certificate Manager that could allow an attacker to extract sensitive information. | |
| Weaknesses | CWE-313 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published: 2026-06-09T08:46:52.528Z
Updated: 2026-06-09T12:54:20.058Z
Reserved: 2026-01-22T13:21:49.113Z
Link: CVE-2026-24349
Updated: 2026-06-09T12:54:14.543Z
Status : Awaiting Analysis
Published: 2026-06-09T10:16:42.967
Modified: 2026-06-09T13:49:39.993
Link: CVE-2026-24349
No data.