Full Report
WinCC Certificate Manager insufficiently protects key material that could allow an attacker to extract sensitive information. Siemens has released a new version for SIMATIC WinCC Unified PC Runtime V21 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.
Analysis Summary
# Vulnerability: Insufficient Protection of Key Material in WinCC Certificate Manager
## CVE Details
- **CVE ID:** CVE-2026-24349
- **CVSS Score:** 7.1 (High) - CVSS v3.1 / 8.2 (High) - CVSS v4.0
- **CWE:** CWE-313: Cleartext Storage in a File or on Disk
## Affected Systems
- **Products:**
- SIMATIC WinCC Unified PC Runtime
- Totally Integrated Automation Portal (TIA Portal)
- **Versions:**
- V16 (All versions)
- V17 (All versions)
- V18 (All versions)
- V19 (All versions)
- V20 (All versions)
- V21 (All versions prior to V21 Update 2)
- **Configurations:** Systems utilizing the WinCC Certificate Manager for operator control and monitoring.
## Vulnerability Description
The WinCC Certificate Manager fails to sufficiently protect cryptographic key material. Specifically, sensitive information is stored in cleartext on the disk or within files. This flaw allows an attacker with access to the file system to extract sensitive key material, potentially compromising the secure communication and authentication mechanisms of the visualization platform.
## Exploitation
- **Status:** Not exploited (No reports of active exploitation or public PoC in the provided advisory)
- **Complexity:** Low
- **Attack Vector:** Local (Requires local access to the system where the material is stored)
## Impact
- **Confidentiality:** High (Extraction of sensitive key material)
- **Integrity:** None (Directly)
- **Availability:** None
## Remediation
### Patches
- **SIMATIC WinCC Unified PC Runtime V21:** Update to **V21 Update 2** or later.
- Download link: hxxps://support[.]industry[.]siemens[.]com/cs/ww/en/view/109991140/
### Workarounds
- **V16 through V20:** No patches are currently planned for these versions.
- **General Mitigations:**
- Restrict system access to qualified personnel only.
- Follow Siemens' operational guidelines for Industrial Security to protect the IT environment.
- Ensure physical and logical access controls are in place to prevent unauthorized local access to the PC Runtime environment.
## Detection
- **Indicators of Compromise:** Unauthorized access to configuration files or directories associated with the WinCC Certificate Manager.
- **Detection methods and tools:** Audit file system access logs for suspicious activity involving certificate storage paths. Use File Integrity Monitoring (FIM) to alert on unauthorized reads or modifications to key material locations.
## References
- **Vendor Advisory:** SSA-063511
- **Siemens ProductCERT:** hxxps://www[.]siemens[.]com/cert/advisories
- **Industrial Security Guidelines:** hxxps://www[.]siemens[.]com/cert/operational-guidelines-industrial-security
- **General Industrial Security Info:** hxxps://www[.]siemens[.]com/industrialsecurity