PT-2013-1037 · Siemens · Simatic Wincc

Aleksandr Tlyapov

·

Publicado

2013-03-19

·

Atualizado

2014-07-25

·

CVE-2014-4685

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Siemens SIMATIC WinCC versions prior to 7.3
Description The issue allows a local user to gain limited elevated privileges of the operating system user by leveraging weak system-object access control. This could potentially be exploited to gain increased access to system resources.
Recommendations For Siemens SIMATIC WinCC versions prior to 7.3, update to version 7.3 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2014-00408
CVE-2014-4685

Produtos afetados

Simatic Wincc