CVE-2014-4684: Medium severity siemens simatic pcs 7 vulnerability
The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a request to TCP port 1433.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4684?
CVE-2014-4684 has been classified with a CVSS score indicating that it poses a significant security risk due to potential privilege escalation.
How do I fix CVE-2014-4684?
To remediate CVE-2014-4684, apply the latest patches provided by Siemens for the affected versions of SIMATIC WinCC and PCS7.
Which products are affected by CVE-2014-4684?
CVE-2014-4684 affects Siemens products, including SIMATIC WinCC versions up to 7.2 and SIMATIC PCS 7 versions up to 8.0.
Can unauthorized users exploit CVE-2014-4684?
CVE-2014-4684 requires authentication, meaning only authenticated users can potentially exploit the vulnerability.
What should I do if I am using an affected version of Siemens software for CVE-2014-4684?
If using an affected version of Siemens software, you should upgrade to a supported version and apply all relevant security patches to mitigate the issue.