CVE-2016-9160: Siemens SIMATIC Pcs 7

High severity, CVSS 8.1. EPSS: 1.4% chance of exploitation in the next 30 days.

A vulnerability in SIEMENS SIMATIC WinCC (All versions < SIMATIC WinCC V7.2) and SIEMENS SIMATIC PCS 7 (All versions < SIMATIC PCS 7 V8.0 SP1) could allow a remote attacker to crash an ActiveX component or leak parts of the application memory if a user is tricked into clicking on a malicious link under certain conditions.

Affected products

  • Siemens SIMATIC Pcs 7: up to and including 8.0
  • Siemens SIMATIC Wincc: up to and including 7.1

Published 2016-12-17. Last modified 2026-06-17.