CVE-2014-4686: Medium severity siemens simatic pcs 7 vulnerability
The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a hardcoded encryption key, which allows remote attackers to obtain sensitive information by extracting this key from another product installation and then employing this key during the sniffing of network traffic on TCP port 1030.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4686?
CVE-2014-4686 has been classified as a medium severity vulnerability.
How do I fix CVE-2014-4686?
To fix CVE-2014-4686, update to Siemens SIMATIC WinCC version 7.3 or later.
What is the impact of CVE-2014-4686?
CVE-2014-4686 allows remote attackers to access sensitive information due to a hardcoded encryption key.
Which software is affected by CVE-2014-4686?
CVE-2014-4686 affects various versions of Siemens SIMATIC WinCC and PCS7 products, specifically prior to version 7.3.
Can I check for CVE-2014-4686 vulnerability in my system?
Yes, checking for the presence of the hardcoded encryption key in affected Siemens software installations can help identify the vulnerability.