5

CVE-2014-8552

The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to read arbitrary files via crafted packets.

Data is provided by the National Vulnerability Database (NVD)
SiemensSimatic Pcs 7 Version7.1 Updatesp1
SiemensSimatic Pcs7 Version7.1 Updatesp3
SiemensSimatic Pcs7 Version7.1 Updatesp4
SiemensSimatic Pcs7 Version8.0 Updatesp1
SiemensSimatic Pcs7 Version8.0 Updatesp2
SiemensSimatic Pcs7 Version8.1
SiemensSimatic Tiaportal Version13.0
SiemensSimatic Tiaportal Version13.0 Update3
SiemensSimatic Tiaportal Version13.0 Update5
SiemensSimatic Wincc Version7.0
SiemensSimatic Wincc Version7.0 Updatesp1
SiemensSimatic Wincc Version7.0 Updatesp2
SiemensSimatic Wincc Version7.0 Updatesp3
SiemensSimatic Wincc Version7.2 Update1
SiemensSimatic Wincc Version7.2 Update2
SiemensSimatic Wincc Version7.2 Update3
SiemensSimatic Wincc Version7.2 Update4
SiemensSimatic Wincc Version7.2 Update5
SiemensSimatic Wincc Version7.2 Update6
SiemensSimatic Wincc Version7.2 Update7
SiemensSimatic Wincc Version7.2 Update8
SiemensSimatic Wincc Version7.3 Update1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.12% 0.278
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.