First published: Fri Feb 07 2014(Updated: )
Directory traversal vulnerability in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to read arbitrary files via crafted packets to TCP port 4999.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SIMATIC WinCC OA | <=3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1698 has a moderate severity rating due to its potential for arbitrary file access.
To fix CVE-2014-1698, upgrade Siemens SIMATIC WinCC OA to version 3.12 P002 or later.
Organizations using Siemens SIMATIC WinCC OA versions prior to 3.12 P002 are affected by CVE-2014-1698.
CVE-2014-1698 facilitates directory traversal attacks, allowing attackers to read arbitrary files on the system.
The attack vector for CVE-2014-1698 involves sending crafted packets to TCP port 4999.