Remarks by ETM regarding SSA-111512 for SIMATIC WinCC OA
This article written by ETM, the company that develops SIMATIC WinCC OA, provides additional insights related to SSA-111512:
On April 6, 2022, "FORESCOUT Vedere Labs" informed us about the intended publication of an article dubbed "OT:ICEFALL" mentioning two vulnerabilities regarding WinCC OA:
- "FSCT-2022-0060: Siemens WinCC OA / ETM PVSS II proprietary protocol with unauthenticated functionality" and
- "FSCT-2022-0059: Siemens WinCC OA Desktop UI Authentication Bypass".
ETM immediately analyzed the claims made in these reports. Based on our level of information, they are based on WinCC Open Architecture (OA) version 3.15.