10

CVE-2014-8551

The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to execute arbitrary code via crafted packets.

Data is provided by the National Vulnerability Database (NVD)
SiemensSimatic Pcs 7 Version7.1 Updatesp1
SiemensSimatic Pcs7 Version7.1 Updatesp3
SiemensSimatic Pcs7 Version7.1 Updatesp4
SiemensSimatic Pcs7 Version8.0 Updatesp1
SiemensSimatic Pcs7 Version8.0 Updatesp2
SiemensSimatic Pcs7 Version8.1
SiemensSimatic Tiaportal Version13.0
SiemensSimatic Tiaportal Version13.0 Update3
SiemensSimatic Tiaportal Version13.0 Update5
SiemensSimatic Wincc Version7.0
SiemensSimatic Wincc Version7.0 Updatesp1
SiemensSimatic Wincc Version7.0 Updatesp2
SiemensSimatic Wincc Version7.0 Updatesp3
SiemensSimatic Wincc Version7.2 Update1
SiemensSimatic Wincc Version7.2 Update2
SiemensSimatic Wincc Version7.2 Update3
SiemensSimatic Wincc Version7.2 Update4
SiemensSimatic Wincc Version7.2 Update5
SiemensSimatic Wincc Version7.2 Update6
SiemensSimatic Wincc Version7.2 Update7
SiemensSimatic Wincc Version7.2 Update8
SiemensSimatic Wincc Version7.3 Update1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.81% 0.9
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.