CVE-2014-4682: Infoleak
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive information via an HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4682?
CVE-2014-4682 is rated as a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2014-4682?
To fix CVE-2014-4682, update your Siemens SIMATIC WinCC or PCS7 software to the latest version that addresses this vulnerability.
What kind of information can be exposed by CVE-2014-4682?
CVE-2014-4682 allows remote attackers to obtain sensitive information via crafted HTTP requests.
Which versions of Siemens software are affected by CVE-2014-4682?
CVE-2014-4682 affects Siemens SIMATIC WinCC versions up to 7.2 and various versions of Siemens SIMATIC PCS7, specifically versions prior to 7.3.
Is there a patch available for CVE-2014-4682?
Yes, Siemens has released patches for the affected versions to mitigate the vulnerabilities listed under CVE-2014-4682.