CVE-2014-8551: Code Injection
The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to execute arbitrary code via crafted packets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8551?
CVE-2014-8551 has been assigned a high severity rating due to the potential for remote code execution.
How do I fix CVE-2014-8551?
To fix CVE-2014-8551, it's recommended to apply the latest updates provided by Siemens for affected software versions.
Which versions of Siemens software are vulnerable to CVE-2014-8551?
Vulnerable versions include Siemens SIMATIC WinCC 7.0 to SP3, 7.2 before Update 9, 7.3 before Update 2, and SIMATIC PCS 7 versions up to 8.1.
What type of attack does CVE-2014-8551 allow?
CVE-2014-8551 allows remote attackers to execute arbitrary code through crafted network packets.
Is there a workaround for CVE-2014-8551?
A definitive workaround is not listed, but minimizing the exposure of vulnerable systems to untrusted networks can reduce risk until updates are applied.