ICSA-18-018-01A: ICSA-18-018-01A Siemens SIMATIC WinCC Add-On (Update A)
CISA advisory · released 2018-01-18
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 2, 2018-02-22 (final)
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Siemens | SIMATIC WinCC Add-On Historian CONNECT ALARM | <=V5.x |
| Siemens | SIMATIC WinCC Add-On PI CONNECT ALARM | <=V2.x |
| Siemens | SIMATIC WinCC Add-On PI CONNECT AUDIT TRAIL | <=V1.x |
| Siemens | SIMATIC WinCC Add-On PM-AGENT | <=V5.x |
| Siemens | SIMATIC WinCC Add-On PM-ANALYZE | <=V7.x |
| Siemens | SIMATIC WinCC Add-On PM-CONTROL | <=V10.x |
| Siemens | SIMATIC WinCC Add-On PM-MAINT | <=V9.x |
| Siemens | SIMATIC WinCC Add-On PM-OPEN EXPORT | <=V7.x |
| Siemens | SIMATIC WinCC Add-On PM-OPEN HOST-S | <=V7.x |
| Siemens | SIMATIC WinCC Add-On PM-OPEN IMPORT | <=V6.x |
| Siemens | SIMATIC WinCC Add-On PM-OPEN PI | <=V7.x |
| Siemens | SIMATIC WinCC Add-On PM-OPEN PV02 | <=V1.x |
| Siemens | SIMATIC WinCC Add-On PM-OPEN TCP/IP | <=V8.x |
| Siemens | SIMATIC WinCC Add-On PM-QUALITY | <=V9.x |
| Siemens | SIMATIC WinCC Add-On SICEMENT IT MIS | <=V7.x |
| Siemens | SIMATIC WinCC Add-On SIPAPER IT MIS | <=V7.x |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2017-11496 · CWE-121
Malformed ASN1 streams in V2C and similar input files can be used to generate stack-based buffer overflows. The vulnerability could allow arbitrary code execution.
- CVE-2017-11497 · CWE-121
Language packs containing malformed filenames could lead to a stack buffer overflow. The vulnerability could allow arbitrary code execution.
- CVE-2017-11498 · CWE-20
Zipped language packs with invalid HTML files could lead to NULL pointer access. The vulnerability could cause denial of service of the remote process.
- CVE-2017-12818 · CWE-119
A stack overflow flaw in the custom XML-parser could allow remote denial of service.
- CVE-2017-12819 · CWE-284
Remote manipulation of the language pack updater could allow NTLM-relay attacks.
- CVE-2017-12820 · CWE-119
Arbitrary memory read from controlled memory pointer could allow remote denial of service.
- CVE-2017-12821 · CWE-119
A memory corruption flaw could allow remote code execution.
- CVE-2017-12822 · CWE-284
The administrative interface can be remotely enabled and disabled without authentication. This could increase the attack surface.
Acknowledgments, as the advisory lists them
- Siemens: reported this vulnerability to CISA.
The advisory's legal notice
All information products included in https://us-cert.cisa.gov/ics are provided "as is" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see https://us-cert.cisa.gov/tlp/.
Sources
DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.