Junglewise Threat Intelligence

CVE-2026-24349: Siemens SIMATIC WinCC Unified PC Runtime cleartext storage in Certificate Manager

CVE-2026-24349 · Severity: high · CVSS 7.1 · Published 2026-06-09

Vendors: Siemens.

Executive brief

A security vulnerability has been identified in Siemens SIMATIC WinCC Unified PC Runtime, a platform used for monitoring and controlling industrial machinery. The software's certificate management tool does not properly protect cryptographic keys, potentially allowing an unauthorized person with local access to the system to steal sensitive information. This could lead to the compromise of secure communications or unauthorized access to the industrial control environment.

Technical details

A vulnerability (CWE-313) exists in the WinCC Certificate Manager component of SIMATIC WinCC Unified PC Runtime. The root cause is the storage of sensitive key material in cleartext or with insufficient protection on the local file system. An attacker with local access to the system can exploit this to extract cryptographic keys or other sensitive data. While the attack requires local access, it does not require specific user privileges or interaction. Siemens has released V21 Update 2 to address this in the latest version branch, but older versions (V16-V20) currently have no planned fix and rely on manual mitigations.

Affected products

  • Siemens SIMATIC WinCC Unified PC Runtime V16 All versions
  • Siemens SIMATIC WinCC Unified PC Runtime V17 All versions
  • Siemens SIMATIC WinCC Unified PC Runtime V18 All versions
  • Siemens SIMATIC WinCC Unified PC Runtime V19 All versions
  • Siemens SIMATIC WinCC Unified PC Runtime V20 All versions
  • Siemens SIMATIC WinCC Unified PC Runtime V21 All versions < V21 Update 2

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory
  • 2026-06-09: patched: Patch available for V21 only

References