VYPR
High severity7.1NVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026

CVE-2026-24349

CVE-2026-24349

Description

SIMATIC WinCC Unified PC Runtime has a key material protection flaw in WinCC Certificate Manager, allowing sensitive information extraction.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SIMATIC WinCC Unified PC Runtime has a key material protection flaw in WinCC Certificate Manager, allowing sensitive information extraction.

Vulnerability

A vulnerability exists in SIMATIC WinCC Unified PC Runtime versions V16 through V21 (prior to V21 Update 2) due to insufficient protection of key material within the WinCC Certificate Manager. This flaw allows for the potential extraction of sensitive information.

Exploitation

An attacker with sufficient access to the affected system could potentially exploit this vulnerability by interacting with the WinCC Certificate Manager to extract sensitive key material. Further details on specific attacker prerequisites or exploitation steps are not disclosed in the available references.

Impact

Successful exploitation of this vulnerability could allow an attacker to extract sensitive information, specifically key material, from the WinCC Certificate Manager. The exact scope and privilege level of the compromise are not detailed in the available references.

Mitigation

Siemens has released an update for SIMATIC WinCC Unified PC Runtime V21, recommending an update to the latest version. For products where fixes are not yet available, Siemens recommends specific countermeasures. The affected versions include SIMATIC WinCC Unified PC Runtime V16, V17, V18, V19, V20, and V21 < V21 Update 2 [1].

References
  1. SSA-063511

AI Insight generated on Jun 9, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

1