PT-2017-17382 · Siemens · Simatic Wincc+2

Published

2017-05-11

·

Updated

2018-06-14

·

CVE-2017-6867

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Siemens SIMATIC WinCC versions 7.3 before Upd 11 Siemens SIMATIC WinCC versions 7.4 before SP1 Siemens SIMATIC WinCC Runtime Professional versions 13 before SP2 Siemens SIMATIC WinCC Runtime Professional versions 14 before SP1 Siemens SIMATIC WinCC (TIA Portal) Professional versions 13 before SP2 Siemens SIMATIC WinCC (TIA Portal) Professional versions 14 before SP1
Description A vulnerability was discovered that could allow an authenticated, remote attacker who is a member of the administrators group to crash services by sending specially crafted messages to the DCOM interface.
Recommendations For Siemens SIMATIC WinCC versions 7.3 before Upd 11, update to Upd 11 or later. For Siemens SIMATIC WinCC versions 7.4 before SP1, update to SP1 or later. For Siemens SIMATIC WinCC Runtime Professional versions 13 before SP2, update to SP2 or later. For Siemens SIMATIC WinCC Runtime Professional versions 14 before SP1, update to SP1 or later. For Siemens SIMATIC WinCC (TIA Portal) Professional versions 13 before SP2, update to SP2 or later. For Siemens SIMATIC WinCC (TIA Portal) Professional versions 14 before SP1, update to SP1 or later.

Fix

RCE

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6867

Affected Products

Simatic Wincc
Simatic Wincc (Tia Portal) Professional
Simatic Wincc Runtime Professional