PT-2017-17382 · Siemens · Simatic Wincc+2
Published
2017-05-11
·
Updated
2018-06-14
·
CVE-2017-6867
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Siemens SIMATIC WinCC versions 7.3 before Upd 11
Siemens SIMATIC WinCC versions 7.4 before SP1
Siemens SIMATIC WinCC Runtime Professional versions 13 before SP2
Siemens SIMATIC WinCC Runtime Professional versions 14 before SP1
Siemens SIMATIC WinCC (TIA Portal) Professional versions 13 before SP2
Siemens SIMATIC WinCC (TIA Portal) Professional versions 14 before SP1
Description
A vulnerability was discovered that could allow an authenticated, remote attacker who is a member of the administrators group to crash services by sending specially crafted messages to the DCOM interface.
Recommendations
For Siemens SIMATIC WinCC versions 7.3 before Upd 11, update to Upd 11 or later.
For Siemens SIMATIC WinCC versions 7.4 before SP1, update to SP1 or later.
For Siemens SIMATIC WinCC Runtime Professional versions 13 before SP2, update to SP2 or later.
For Siemens SIMATIC WinCC Runtime Professional versions 14 before SP1, update to SP1 or later.
For Siemens SIMATIC WinCC (TIA Portal) Professional versions 13 before SP2, update to SP2 or later.
For Siemens SIMATIC WinCC (TIA Portal) Professional versions 14 before SP1, update to SP1 or later.
Fix
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simatic Wincc
Simatic Wincc (Tia Portal) Professional
Simatic Wincc Runtime Professional