Improper Access Control in SIMATIC WinCC OA by Siemens
CVE-2018-13799
9.1CRITICAL
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 12 September 2018
What is CVE-2018-13799?
A vulnerability exists in SIMATIC WinCC OA that allows unauthorized access due to improper access control mechanisms. An attacker with network access to the SIMATIC WinCC OA server on port 5678/TCP can exploit this issue without requiring user privileges or interaction. This could lead to potential privilege escalation, jeopardizing the integrity and availability of the system. As of the advisory's publication, there has been no known public exploitation of this vulnerability.
Affected Version(s)
SIMATIC WinCC OA V3.14 and prior SIMATIC WinCC OA V3.14 and prior : All versions < V3.14-P021