CVE-2014-1697: High severity Siemens Simatic Wincc Open Architecture vulnerability
Published Feb 7, 2014
·Updated
The integrated web server in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to execute arbitrary code via crafted packets to TCP port 4999.
Affected Software
1 affected component
Siemens Simatic Wincc Open Architecture<=3.12
Event History
Feb 7, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·04:52 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1697?
CVE-2014-1697 is considered a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2014-1697?
To mitigate CVE-2014-1697, update Siemens SIMATIC WinCC OA to version 3.12 P002 or later.
3
What are the potential impacts of CVE-2014-1697?
The exploitation of CVE-2014-1697 may allow remote attackers to execute arbitrary code on affected systems.
4
Which versions of Siemens SIMATIC WinCC OA are affected by CVE-2014-1697?
CVE-2014-1697 affects all versions of Siemens SIMATIC WinCC OA prior to version 3.12 P002.
5
How can I determine if my system is vulnerable to CVE-2014-1697?
To check for vulnerability to CVE-2014-1697, verify if your Siemens SIMATIC WinCC OA version is below 3.12 P002.