Remarks by ETM regarding SSA-111512 for SIMATIC WinCC OA

This article written by ETM, the company that develops SIMATIC WinCC OA, provides additional insights related to SSA-111512:

On April 6, 2022, "FORESCOUT Vedere Labs" informed us about the intended publication of an article dubbed "OT:ICEFALL" mentioning two vulnerabilities regarding WinCC OA:

  • "FSCT-2022-0060: Siemens WinCC OA / ETM PVSS II proprietary protocol with unauthenticated functionality" and
  • "FSCT-2022-0059: Siemens WinCC OA Desktop UI Authentication Bypass".

ETM immediately analyzed the claims made in these reports. Based on our level of information, they are based on WinCC Open Architecture (OA) version 3.15.

We thank the researchers of FORESCOUT for identifying a security problem if one does not use and correctly configure available security features of the product:

  • Server-side authentication is available in the version under evaluation (V3.15, released in January 2017) but not configured by default.
  • Additionally, certificate-based authenticated and encrypted communication via AD (active directory) integration and
  • Kerberos has been available since V3.8 (released November 2008) but must be configured the right way

Beginning with version 3.17, we made server-side authentication the default configuration to avoid the problems identified. WinCC OA has always provided a wide range of possible system configurations to cover individual needs of our customers, partners and their businesses. This also extends to security and the possibility to integrate the product in a wide range of operational environments.

ETM strongly recommends to always use the latest version of WinCC OA and its security guide to find the best combination of security features for a project: WinCC OA user management, external user management with single sign-on, Kerberos encryption, server-side authentication, right choice of cipher suites, secure connection to field devices, ...

ETM is aware that security is a continuous process that needs constant monitoring to maintain the state of the art. Hence, we support our customers pro-actively to avoid misconfigurations that could lead to vulnerable installations in the security lifecycle of their SCADA installations and products by offering: