HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-24349Published Modified CNA siemens

CVE-2026-24349: A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC Runt

A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC Runtime V20 (All versions), SIMATIC WinCC Unified PC Runtime V21 (All versions < V21 Update 2). Insufficient protection of key material in WinCC Certificate Manager that could allow an attacker to extract sensitive information.

Metrics

CVSS v4.0
8.2
Severity
HIGH
Fixed in
*
Affected Products
6

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An insufficient key-material protection vulnerability exists in the WinCC Certificate Manager component of Siemens SIMATIC WinCC Unified PC Runtime (versions V16 through V21 prior to V21 Update 2). The flaw is reached locally with no authentication required, meaning an attacker who already has a shell or process on the host can exploit it without any credentials. Successful exploitation allows the attacker to extract sensitive cryptographic key material and certificate data from the system. A patched-image rebuild at V21 Update 2 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection capability is available across every HarborGuard environment: the CVE is ingested from upstream Siemens and NVD advisory feeds within minutes of publication and matched against customer images in registries and CI pipelines, including custom-built images that bundle WinCC Unified PC Runtime components.

Available
Triage

HarborGuard is capable of scoring this finding at CVSS 8.2 (High) using the v4.0 vector and applying per-environment compliance policy weighting to prioritize routing; triage alerts are directed to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild pinned to V21 Update 2 becomes available on HarborGuard once the updated base is resolvable from upstream sources. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test pass, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityNot required

    The attacker needs an existing shell or process on the host; no network access to the service is required.

  • AuthenticationNot required

    No credentials of any privilege level are needed to trigger the vulnerability.

  • Victim interactionNot required

    Exploitation is entirely attacker-driven and does not require any action from a user or operator on the target system.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other variable environmental factors.

Blast Radius

  • Reads cryptographic key material stored by the WinCC Certificate Manager, including private keys associated with issued certificates.
  • Reads sensitive certificate data scoped to the local system, which can expose trust relationships within the OT or ICS network segment.
  • Extracted key material can be used outside this host to impersonate the affected system or decrypt traffic protected by those certificates.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-24349 is active across all environments scanning images that include SIMATIC WinCC Unified PC Runtime components, with ingestion typically completing within minutes of advisory publication. Where a customer image includes an affected runtime version (V16 through V21 prior to V21 Update 2), a rebuilt image at V21 Update 2 is made available as soon as the patched upstream layer resolves. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, executes a regression test run, and opens a pull request against affected workloads; for high-severity issues, median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit auto-remediation, the finding is surfaced in the triage queue with CVSS 8.2 scoring and policy-weighted priority so the owning team can act manually.

See how HarborGuard automates this

Fix available

*V21 Update 2
Affected packages
  • Siemens / SIMATIC WinCC Unified PC Runtime V16
    < * (from 0)
  • Siemens / SIMATIC WinCC Unified PC Runtime V17
    < * (from 0)
  • Siemens / SIMATIC WinCC Unified PC Runtime V18
    < * (from 0)
  • Siemens / SIMATIC WinCC Unified PC Runtime V19
    < * (from 0)
  • Siemens / SIMATIC WinCC Unified PC Runtime V20
    < * (from 0)
  • Siemens / SIMATIC WinCC Unified PC Runtime V21
    < V21 Update 2 (from 0)
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N