Improper Access Control in SIMATIC WinCC OA by Siemens
CVE-2018-13799
9.1CRITICAL
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 12 September 2018
Summary
A vulnerability exists in SIMATIC WinCC OA that allows unauthorized access due to improper access control mechanisms. An attacker with network access to the SIMATIC WinCC OA server on port 5678/TCP can exploit this issue without requiring user privileges or interaction. This could lead to potential privilege escalation, jeopardizing the integrity and availability of the system. As of the advisory's publication, there has been no known public exploitation of this vulnerability.
Affected Version(s)
SIMATIC WinCC OA V3.14 and prior SIMATIC WinCC OA V3.14 and prior : All versions < V3.14-P021
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved