Synopsis
A remotely exploitable Unrestricted Upload of File with Dangerous Type vulnerability has been identified in SIMATIC PCS7 v8 through v9.0, SIMATIC WinCC (TIA Portal) v14 through v15.1.
Description
The SIMATIC WinCC DataMonitor web application of the affected products allows an authenticated user with network access to the WinCC DataMonitor application to upload arbitrary ASPX code. Successful exploitation requires no user interaction and may impact the confidentiality, integrity, and availability of the affected device. The vulnerability is relevant only in situations where an attacker has access via the web interface but not to the directory structure.
Solution
Perform vendor recommended mitigations and apply available vendor upgrades.