Simatic Wincc Runtime Advanced
Vendor:
First CVE: Apr 17, 2019 · Active for 7 years
12
Total CVEs
More Total CVEs than 91% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Simatic Wincc Runtime Advanced over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 17, 2019
7 years ago
Most Recent CVE
May 12, 2021
1,903 days ago
CVE Severity & Scoring
Simatic Wincc Runtime Advanced12 CVEs
25%
67%
8%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (8.3%)
Network10 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (8.3%)
Attack Complexity
Low11 (91.7%)
High1 (8.3%)
Unknown0 (0.0%)
User Interaction
None12 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High1 (8.3%)
None11 (91.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3449MEDIUM An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms | Mar 25, 2021 | 5.9 | 57 | NO | NO |
CVE-2021-27384CRITICAL A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels | May 12, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-6575HIGH A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V2.7), SIMATI | Apr 17, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-6568HIGH The webserver of the affected devices contains a vulnerability that may lead to
a denial of service condition. An attacker may cause a denial of service
situation which leads to | Apr 17, 2019 | 7.5 | 25 | NO | NO |
CVE-2021-27385HIGH A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels | May 12, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-27383HIGH A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels | May 12, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-27386HIGH A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels | May 12, 2021 | 7.5 | 23 | NO | NO |
CVE-2021-25662HIGH A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels | May 12, 2021 | 7.5 | 23 | NO | NO |
CVE-2021-25660HIGH A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels | May 12, 2021 | 7.5 | 23 | NO | NO |
CVE-2020-7580MEDIUM A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 | Jun 10, 2020 | 6.7 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Simatic Wincc Runtime Advanced
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 16 | 7 | 7.8 | 1.8% | 0 | 0 |
| 15.1 | 8 | 7.8 | 1.7% | 0 | 0 |