First published: Fri Feb 07 2014(Updated: )
The integrated web server in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to execute arbitrary code via crafted packets to TCP port 4999.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SIMATIC WinCC OA (Open Architecture) | <=3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1697 is considered a critical vulnerability due to its potential to allow remote code execution.
To mitigate CVE-2014-1697, update Siemens SIMATIC WinCC OA to version 3.12 P002 or later.
The exploitation of CVE-2014-1697 may allow remote attackers to execute arbitrary code on affected systems.
CVE-2014-1697 affects all versions of Siemens SIMATIC WinCC OA prior to version 3.12 P002.
To check for vulnerability to CVE-2014-1697, verify if your Siemens SIMATIC WinCC OA version is below 3.12 P002.