CVE-2026-24349: A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC Runt
A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC Runtime V20 (All versions), SIMATIC WinCC Unified PC Runtime V21 (All versions < V21 Update 2). Insufficient protection of key material in WinCC Certificate Manager that could allow an attacker to extract sensitive information.
Metrics
- CVSS v4.0
- 8.2
- Severity
- HIGH
- Fixed in
- *
- Affected Products
- 6
HarborGuard Analysis
Synopsis
An insufficient key-material protection vulnerability exists in the WinCC Certificate Manager component of Siemens SIMATIC WinCC Unified PC Runtime (versions V16 through V21 prior to V21 Update 2). The flaw is reached locally with no authentication required, meaning an attacker who already has a shell or process on the host can exploit it without any credentials. Successful exploitation allows the attacker to extract sensitive cryptographic key material and certificate data from the system. A patched-image rebuild at V21 Update 2 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection capability is available across every HarborGuard environment: the CVE is ingested from upstream Siemens and NVD advisory feeds within minutes of publication and matched against customer images in registries and CI pipelines, including custom-built images that bundle WinCC Unified PC Runtime components.
AvailableHarborGuard is capable of scoring this finding at CVSS 8.2 (High) using the v4.0 vector and applying per-environment compliance policy weighting to prioritize routing; triage alerts are directed to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableA patched-image rebuild pinned to V21 Update 2 becomes available on HarborGuard once the updated base is resolvable from upstream sources. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test pass, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityNot required
The attacker needs an existing shell or process on the host; no network access to the service is required.
- AuthenticationNot required
No credentials of any privilege level are needed to trigger the vulnerability.
- Victim interactionNot required
Exploitation is entirely attacker-driven and does not require any action from a user or operator on the target system.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other variable environmental factors.
Blast Radius
- Reads cryptographic key material stored by the WinCC Certificate Manager, including private keys associated with issued certificates.
- Reads sensitive certificate data scoped to the local system, which can expose trust relationships within the OT or ICS network segment.
- Extracted key material can be used outside this host to impersonate the affected system or decrypt traffic protected by those certificates.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-24349 is active across all environments scanning images that include SIMATIC WinCC Unified PC Runtime components, with ingestion typically completing within minutes of advisory publication. Where a customer image includes an affected runtime version (V16 through V21 prior to V21 Update 2), a rebuilt image at V21 Update 2 is made available as soon as the patched upstream layer resolves. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, executes a regression test run, and opens a pull request against affected workloads; for high-severity issues, median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit auto-remediation, the finding is surfaced in the triage queue with CVSS 8.2 scoring and policy-weighted priority so the owning team can act manually.
Fix available
- Siemens / SIMATIC WinCC Unified PC Runtime V16< * (from 0)
- Siemens / SIMATIC WinCC Unified PC Runtime V17< * (from 0)
- Siemens / SIMATIC WinCC Unified PC Runtime V18< * (from 0)
- Siemens / SIMATIC WinCC Unified PC Runtime V19< * (from 0)
- Siemens / SIMATIC WinCC Unified PC Runtime V20< * (from 0)
- Siemens / SIMATIC WinCC Unified PC Runtime V21< V21 Update 2 (from 0)
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N