Siemens Industry Online Support
Siemens AG
Entry type: FAQ Entry ID: 68585055, Entry date: 03/21/2013

Which security measures help against unauthorized access to computer systems with WinCC flexible?

  • Entry
  • Associated product(s)

The SQL server of WinCC flexible up to and including the version 2005 SP1 works with a fixed user account. WinCC flexible 2007, 2008 and 2008 SP2 use the same version of the SQL server with a fixed user account for the "Save as Version" function. Both are potential security risks.

Only WinCC flexible Engineering Stations and not Runtime Stations are infected.

Install the latest version of WinCC flexible 2008 SP3 and remove any old instances of the SQL server. Removing old instances of the SQL server is not necessary with Windows 7, because the MSDE (Microsoft SQL Server Desktop Engine) is not available for Windows 7.

More information about "What remedies are there for weak points in WinCC flexible 2008 and WinCC V11?" is available in Entry ID: 59057488.
More information about the updates for WinCC flexible 2008 Service Pack 3 is available in Entry ID: 58860033.

Proceed as follows to uninstall and check available instances of WinCC flexible SQL.

No. Procedure
1 Click "Start > Settings > Control Panel".

Fig. 01

2 Click "Add or Remove Programs".

Fig. 02

3 If there, remove the "Microsoft SQL Server Desktop Engine (WinCCflexible)" program. Click "Remove" to uninstall the software.

Fig. 03

You can use the Cleanup Support Tool to uninstall the MSDE (Microsoft SQL Server Desktop Engine). The Cleanup Support Tool is available in Entry ID: 28465761.

4  To check that the WinCC flexible SQL instance has been uninstalled correctly you click "Start > Settings > Control Panel".

Fig. 04

5 Click "Administrative Tools".

Fig. 05

  Click "Services".

Fig. 06

6 If the "MSSQL$WinCCFLEXIBLE" service still exists, the WinCC flexible instance has not been uninstalled correctly.

Fig. 07

7 In this case you disable the "MSSQL$WinCCFLEXIBLE" service by right-clicking the service and selecting "Stop".

Fig. 08

8 Right-click the service and select "Properties".

Fig. 09

9 Select "Startup type:" and "Disabled".

Fig. 10

By changing the startup type from "Automatic" to "Disabled" you prevent the service from restarting when you restart the computer.