CVE-2014-4685: Medium severity siemens simatic pcs 7 vulnerability
Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveraging weak system-object access control.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4685?
CVE-2014-4685 has been classified as a medium severity vulnerability due to the risks associated with privilege escalation.
How do I fix CVE-2014-4685?
To remediate CVE-2014-4685, you should apply the latest security patches provided by Siemens for affected versions.
What products are affected by CVE-2014-4685?
CVE-2014-4685 affects Siemens SIMATIC WinCC versions prior to 7.3 and specific versions of Siemens SIMATIC PCS 7.
Can local users exploit CVE-2014-4685?
Yes, local users can potentially exploit CVE-2014-4685 to gain higher privileges through weak access controls.
Is there a workaround for CVE-2014-4685?
Currently, the recommended solution for CVE-2014-4685 is to update the software to a secure version rather than relying on workarounds.