Improper Access Control in SIMATIC WinCC OA by Siemens
CVE-2018-13799

9.1CRITICAL

Key Information:

Vendor
Siemens
Vendor
CVE Published:
12 September 2018

Summary

A vulnerability exists in SIMATIC WinCC OA that allows unauthorized access due to improper access control mechanisms. An attacker with network access to the SIMATIC WinCC OA server on port 5678/TCP can exploit this issue without requiring user privileges or interaction. This could lead to potential privilege escalation, jeopardizing the integrity and availability of the system. As of the advisory's publication, there has been no known public exploitation of this vulnerability.

Affected Version(s)

SIMATIC WinCC OA V3.14 and prior SIMATIC WinCC OA V3.14 and prior : All versions < V3.14-P021

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.