CVE-2014-1698: Path Traversal
Published Feb 7, 2014
·Updated
Directory traversal vulnerability in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to read arbitrary files via crafted packets to TCP port 4999.
Affected Software
1 affected component
Siemens Simatic Wincc Open Architecture<=3.12
Event History
Feb 7, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·04:52 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1698?
CVE-2014-1698 has a moderate severity rating due to its potential for arbitrary file access.
2
How do I fix CVE-2014-1698?
To fix CVE-2014-1698, upgrade Siemens SIMATIC WinCC OA to version 3.12 P002 or later.
3
Who is affected by CVE-2014-1698?
Organizations using Siemens SIMATIC WinCC OA versions prior to 3.12 P002 are affected by CVE-2014-1698.
4
What kind of attack does CVE-2014-1698 facilitate?
CVE-2014-1698 facilitates directory traversal attacks, allowing attackers to read arbitrary files on the system.
5
What is the attack vector for CVE-2014-1698?
The attack vector for CVE-2014-1698 involves sending crafted packets to TCP port 4999.