Remote Code Execution in Siemens SIMATIC WinCC OA Web Server
CVE-2014-1697

Currently unrated

Key Information:

Vendor
Siemens
Vendor
CVE Published:
7 February 2014

Summary

The web server integrated within Siemens SIMATIC WinCC OA up to version 3.12 P002 is vulnerable to remote code execution. Attackers can exploit this vulnerability by sending specially crafted packets to TCP port 4999, potentially allowing them to execute arbitrary code on the affected system. This poses significant risks to organizations utilizing the software in their operations, highlighting the need for timely updates and robust security practices.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.