PT-2017-17382 · Siemens · Simatic Wincc+2

Publicado

2017-05-11

·

Atualizado

2018-06-14

·

CVE-2017-6867

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Siemens SIMATIC WinCC versions 7.3 before Upd 11 Siemens SIMATIC WinCC versions 7.4 before SP1 Siemens SIMATIC WinCC Runtime Professional versions 13 before SP2 Siemens SIMATIC WinCC Runtime Professional versions 14 before SP1 Siemens SIMATIC WinCC (TIA Portal) Professional versions 13 before SP2 Siemens SIMATIC WinCC (TIA Portal) Professional versions 14 before SP1
Description A vulnerability was discovered that could allow an authenticated, remote attacker who is a member of the administrators group to crash services by sending specially crafted messages to the DCOM interface.
Recommendations For Siemens SIMATIC WinCC versions 7.3 before Upd 11, update to Upd 11 or later. For Siemens SIMATIC WinCC versions 7.4 before SP1, update to SP1 or later. For Siemens SIMATIC WinCC Runtime Professional versions 13 before SP2, update to SP2 or later. For Siemens SIMATIC WinCC Runtime Professional versions 14 before SP1, update to SP1 or later. For Siemens SIMATIC WinCC (TIA Portal) Professional versions 13 before SP2, update to SP2 or later. For Siemens SIMATIC WinCC (TIA Portal) Professional versions 14 before SP1, update to SP1 or later.

Correção

RCE

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6867

Produtos afetados

Simatic Wincc
Simatic Wincc (Tia Portal) Professional
Simatic Wincc Runtime Professional