CVE-2014-8552: Infoleak
The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to read arbitrary files via crafted packets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8552?
CVE-2014-8552 has been assigned a medium severity rating due to its ability to allow remote attackers to read arbitrary files.
How do I fix CVE-2014-8552?
To mitigate CVE-2014-8552, users should upgrade to the latest versions of affected Siemens software which contain security patches.
Which Siemens products are affected by CVE-2014-8552?
CVE-2014-8552 affects Siemens SIMATIC WinCC, SIMATIC PCS 7, and TIA Portal versions specified in the vulnerability details.
Can CVE-2014-8552 be exploited remotely?
Yes, CVE-2014-8552 can be exploited remotely through crafted packets that target vulnerable Siemens software.
What versions of SIMATIC WinCC are vulnerable to CVE-2014-8552?
SIMATIC WinCC versions 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2 are vulnerable to CVE-2014-8552.