CVE-2023-30897: Siemens Wincc

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability has been identified in SIMATIC WinCC (All versions < V7.5.2.13). Affected applications fail to set proper access rights for their installation folder if a non-default installation path was chosen during installation. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.

Affected products

  • Siemens Wincc: before 7.5.2.13 (fixed in 7.5.2.13)

Published 2023-06-13. Last modified 2026-06-17.