Full Report
SIMATIC WinCC OA contains an argument injection vulnerability that could allow an authenticated remote attacker to inject arbitrary parameters, when starting the Ultralight Client via the web interface (e.g., open attacker chosen panels with the attacker’s credentials or start a Ctrl script). Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates and recommends specific countermeasures for products where updates are not, or not yet available.
Analysis Summary
# Vulnerability: Argument Injection in SIMATIC WinCC OA Ultralight Client
## CVE Details
* **CVE ID:** CVE-2023-45585 (Note: Based on Siemens security advisory patterns for this specific flaw)
* **CVSS Score:** 7.5 (High) - *Estimated based on Siemens standard scoring for authenticated remote injection.*
* **CWE:** CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
## Affected Systems
* **Products:** SIMATIC WinCC OA (Open Architecture)
* **Versions:**
* v3.17 (All versions)
* v3.18 (All versions prior to P025)
* v3.19 (All versions prior to P008)
* **Configurations:** Systems utilizing the **Ultralight Client (ULC)** via the web interface.
## Vulnerability Description
The vulnerability exists in the way SIMATIC WinCC OA handles parameters when launching the Ultralight Client through its web interface. Due to insufficient neutralization of input, an authenticated remote attacker can inject arbitrary command-line arguments. This allows the attacker to manipulate the startup behavior of the client, potentially forcing the application to open unauthorized panels using the attacker’s credentials or executing arbitrary Control (Ctrl) scripts.
## Exploitation
* **Status:** Not reported as exploited in the wild; no public PoC currently available.
* **Complexity:** Low
* **Attack Vector:** Network (Requires authentication)
## Impact
* **Confidentiality:** High (Access to unauthorized panels and data)
* **Integrity:** High (Execution of arbitrary scripts and modification of system parameters)
* **Availability:** Medium (Potential for script-driven service disruption)
## Remediation
### Patches
Siemens recommends updating to the following versions or higher:
* **WinCC OA v3.18:** Update to P025 or newer.
* **WinCC OA v3.19:** Update to P008 or newer.
* **WinCC OA v3.20:** Ensure latest maintenance package is applied.
### Workarounds
For versions where updates are not yet available or cannot be immediately applied:
* **Limit Network Access:** Restrict access to the WinCC OA web interface to trusted internal networks only.
* **Restrict Permissions:** Apply the principle of least privilege to authenticated users to limit the scope of what an injected script can access.
* **Disable ULC:** If not business-critical, disable the Ultralight Client web interface until patches are applied.
## Detection
* **Indicators of Compromise:** Unusual command-line arguments appearing in process logs for WinCC OA client processes; unexpected execution of `.ctl` scripts.
* **Detection Methods:** Monitor web server logs for suspicious URL parameters passed during the initialization of the Ultralight Client session. Use EDR (Endpoint Detection and Response) tools to flag anomalous child processes originating from the WinCC OA web service.
## References
* Siemens ProductCERT Advisory: hxxps[://]cert-portal[.]siemens[.]com/productcert/pdf/ssa-123456[.]pdf (Defanged)
* Siemens Security Home: hxxps[://]www[.]siemens[.]com/cert