# Siemens WinCC Certificate Manager Leaks Cryptographic Keys in Cleartext Storage Flaw
## The Threat
Siemens has disclosed a critical vulnerability in WinCC Certificate Manager that exposes cryptographic key material stored in cleartext on disk, allowing local attackers to extract sensitive information used to secure industrial control systems worldwide. Tracked as CVE-2026-24349, the flaw stems from insufficient protection of key material during storage—a basic cryptographic hygiene failure in a product deployed across critical infrastructure including power grids, manufacturing facilities, transportation systems, and healthcare networks.
The vulnerability affects all versions of SIMATIC WinCC Unified PC Runtime from V16 through V20, with V21 vulnerable until Update 2. WinCC Certificate Manager is a core component of Siemens' industrial automation platform, responsible for managing SSL/TLS certificates and private keys that authenticate communication between SCADA systems, HMI terminals, and other networked industrial devices. The cleartext storage flaw means that an attacker with local file system access—whether through compromised credentials, physical access, or lateral movement within a network—can trivially recover encryption keys that should be protected.
This is not a remote vulnerability requiring complex exploitation; any account with local access to an affected system can read the exposed keys from disk. In industrial environments where legacy security practices are common and system isolation is imperfect, this represents a straightforward path to compromise.
## Severity and Impact
| Attribute | Details |
|-----------|---------|
| CVE ID | CVE-2026-24349 |
| CVSS Base Score | 7.1 (HIGH) |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
| Attack Vector | Local |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| CWE | CWE-313 (Cleartext Storage in a File or on Disk) |
| Impact | High confidentiality impact; system-wide compromise of cryptographic protections |
The CVSS 7.1 rating reflects the local attack vector but understates the strategic risk: compromised certificate material can be used to impersonate systems, perform man-in-the-middle attacks on industrial communications, or decrypt historical traffic. In manufacturing and energy sectors, this enables attackers to inject forged commands into control loops or sabotage monitoring.
## Affected Products
The following versions of SIMATIC WinCC Unified PC Runtime are confirmed vulnerable:
## Mitigations
Immediate Actions:
1. Update to V21.0.2 or later — Siemens has released a patched version for V21. Organizations running this version should prioritize immediate deployment of Update 2, available through Siemens support portal.
2. No patch available for V16–V20 — Siemens has not released fixes for legacy versions. Organizations must implement defense-in-depth controls:
- Restrict local file system access to systems running affected versions using OS-level access controls and privileged account management.
- Implement physical security controls on systems housing Certificate Manager installations.
- Disable unnecessary local access — disable RDP, SSH, and other remote access services on systems where only automation engineers require access.
3. Network Segmentation — Isolate WinCC systems from general corporate networks using firewalls and DMZ configurations. Prevent lateral movement from compromised workstations or web-facing systems.
4. Key Rotation and Monitoring — After patching or deploying mitigations, rotate all certificates and keys managed by affected systems. Implement file integrity monitoring on Certificate Manager storage locations to detect unauthorized access attempts.
5. Credential Hardening — Apply the principle of least privilege to all accounts with access to WinCC systems. Use multi-factor authentication where feasible in industrial environments.
## References
---
## HackWire Analysis
This vulnerability exposes a persistent architectural weakness in industrial security: cleartext key storage in production systems. Siemens' failure to encrypt certificate material at rest represents a regression to pre-2010 cryptographic practices—this should not be a surprise finding in 2026.
The geography matters here. WinCC deployments span critical infrastructure worldwide, with particularly dense concentrations in Germany, North America, and Europe. Power utilities, water treatment facilities, and manufacturing plants are now running systems where any administrator, contractor, or compromised user account can extract cryptographic material that anchors system security. In operational environments where air-gap assumptions are eroding and remote management is expanding, this dramatically lowers the barrier to persistent compromise.
The CVSS 7.1 rating reflects the local-only attack vector, but the strategic risk is higher. Compromised keys enable attackers to forge legitimate system messages, decrypt supervisory traffic, or masquerade as trusted components. Consider a scenario where a contractor's laptop is compromised: that attacker gains a foothold to extract keys from any WinCC system the contractor accessed. Those keys become persistent backdoors.
Siemens' decision not to backport patches to V16–V20 is pragmatic but leaves the majority of deployed WinCC systems without remediation. Organizations on legacy versions now face a binary choice: accept that their cryptographic protections are already compromised, or undertake costly system replacement. Many will choose neither—they'll patch the OS, lock down accounts, and assume the risk. This is how industrial networks degrade over time.
For defenders:** This is an urgent signal to audit file permissions and access controls on all Siemens automation infrastructure. If you're running V16–V20, assume keys are extractable and plan for detection of their abuse rather than prevention. If you can upgrade to V21.0.2, do it before attackers do. — **HackWire Editorial
## Related Coverage