A local attacker can exploit a vulnerability in Siemens TIA Portal WinCC Unified PC Runtime to disclose information. The vulnerability has a CVSS base score of 7.1 (High) and affects versions prior to V21 Update 2. A mitigation is available, though the specific patch version is not provided in the advisory.
[WID-SEC-2026-1826] Siemens TIA Portal (WinCC Unified PC Runtime): Schwachstelle ermöglicht Offenlegung von Informationen CVSS Base Score 7.1 (hoch) CVSS Temporal Score 6.2 (mittel) Remoteangriff nein Datum 08.06.2026 Stand 09.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges Windows Produktbeschreibung TIA-Portal ist ein Automatisierungsframework für Steuerungen und andere Automatisierungsgeräte der SIMATIC-Serie. Produkte 08.06.2026 Siemens TIA Portal WinCC Unified PC Runtime V21 <Update 2 Angriff Angriff Ein lokaler Angreifer kann eine Schwachstelle in Siemens TIA Portal ausnutzen, um Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben