CVE-2026-24349 | Siemens SIMATIC WinCC Unified PC Runtime V21 Certificate cleartext storage in file (ssa-063511)
A vulnerability described as problematic has been identified in Siemens SIMATIC WinCC Unified PC Runtime V16, SIMATIC WinCC Unified PC Runtime V17, SIMATIC WinCC Unified PC Runtime V18, SIMATIC WinCC Unified PC Runtime V19, SIMATIC WinCC Unified PC Runtime V20 and SIMATIC WinCC Unified PC Runtime V21. The impacted element is an unknown function of the component Certificate Handler. The manipulation results in cleartext storage in a file or on disk.
This vulnerability is identified as CVE-2026-24349. The attack is only possible with local access. There is not any exploit available.
Upgrading the affected component is recommended.