CVE-2024-35783: Siemens SIMATIC Batch

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server 2022 (All versions < V2022 SP1 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC06), SIMATIC Process Historian 2020 (All versions < V2020 SP2 Update 5), SIMATIC Process Historian 2022 (All versions < V2022 SP1 Update 2), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 5), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 3), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 18), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5). The affected products run their DB server with elevated privileges which could allow an authenticated attacker to execute arbitrary OS commands with administrative privileges.

Affected products

  • Siemens SIMATIC Batch: any version
  • Siemens SIMATIC Batch v9.1: any version
  • Siemens SIMATIC Information Server 2020
  • Siemens SIMATIC Information Server 2022
  • Siemens SIMATIC Pcs 7 v9.1: before V9.1 SP2 UC06 (fixed in V9.1 SP2 UC06)
  • Siemens SIMATIC Process Historian 2020
  • Siemens SIMATIC Process Historian 2022
  • Siemens SIMATIC Wincc: from 7.4, before 7.5_sp2_update_18 (fixed in 7.5_sp2_update_18); from 8.0, before 8.0_update_5 (fixed in 8.0_update_5)
  • Siemens SIMATIC Wincc Runtime Professional v18: before V18 Update 5 (fixed in V18 Update 5)
  • Siemens SIMATIC Wincc Runtime Professional v19: before V19 Update 3 (fixed in V19 Update 3)
  • Siemens SIMATIC Wincc v7.4: any version
  • Siemens SIMATIC Wincc v7.5
  • Siemens SIMATIC Wincc v8.0: before V8.0 Update 5 (fixed in V8.0 Update 5)

Published 2024-09-10. Last modified 2026-06-17.