First published: Wed Nov 26 2014(Updated: )
The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to read arbitrary files via crafted packets.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SIMATIC PCS 7 | =7.1-sp1 | |
Siemens Simatic PCS 7 | =7.1-sp3 | |
Siemens Simatic PCS 7 | =7.1-sp4 | |
Siemens Simatic PCS 7 | =8.0-sp1 | |
Siemens Simatic PCS 7 | =8.0-sp2 | |
Siemens Simatic PCS 7 | =8.1 | |
Siemens SIMATIC TIA Portal | =13.0 | |
Siemens SIMATIC TIA Portal | =13.0-3 | |
Siemens SIMATIC TIA Portal | =13.0-5 | |
Siemens Simatic WinCC | =7.0 | |
Siemens Simatic WinCC | =7.0-sp1 | |
Siemens Simatic WinCC | =7.0-sp2 | |
Siemens Simatic WinCC | =7.0-sp3 | |
Siemens Simatic WinCC | =7.2-1 | |
Siemens Simatic WinCC | =7.2-2 | |
Siemens Simatic WinCC | =7.2-3 | |
Siemens Simatic WinCC | =7.2-4 | |
Siemens Simatic WinCC | =7.2-5 | |
Siemens Simatic WinCC | =7.2-6 | |
Siemens Simatic WinCC | =7.2-7 | |
Siemens Simatic WinCC | =7.2-8 | |
Siemens Simatic WinCC | =7.3-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8552 has been assigned a medium severity rating due to its ability to allow remote attackers to read arbitrary files.
To mitigate CVE-2014-8552, users should upgrade to the latest versions of affected Siemens software which contain security patches.
CVE-2014-8552 affects Siemens SIMATIC WinCC, SIMATIC PCS 7, and TIA Portal versions specified in the vulnerability details.
Yes, CVE-2014-8552 can be exploited remotely through crafted packets that target vulnerable Siemens software.
SIMATIC WinCC versions 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2 are vulnerable to CVE-2014-8552.