CVE detail
CVE-2014-4686
The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a hardcoded encryption key, which allows remote attackers to obtain sensitive information by extracting this key from another product installation and then employing this key during the sniffing of network traffic on TCP port 1030.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 11.0 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
2 source links · newest first
Siemens has released service packs and updates to address several vulnerabilities affecting the company’s SIMATIC STEP 7 and SIMATIC WinCC solutions. Researchers identified a total of four security holes affecting SIMATIC STEP 7 (TIA Portal), an engineering application used to configure and program SIMATIC controllers and standard PCs running WinAC RTX.
newswww.securityweek.comFeb 17, 2015, 1:20 PMSiemens has released version 7.3 of the SIMATIC WinCC supervisory control and data acquisition (SCADA) system to address several vulnerabilities, most of which can be exploited remotely.
newswww.securityweek.comJul 28, 2014, 12:32 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2017-12069CVSS 8.2 · High
An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are…
- CVE-2014-4685CVSS 4.6 · Medium
Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveraging weak system-object access control.
- CVE-2014-4684CVSS 6.0 · Medium
The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a request to TCP port 1433.
- CVE-2014-4683CVSS 4.9 · Medium
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a (1) HTTP or (2) HTTPS r…
- CVE-2014-4682CVSS 5.0 · Medium
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive information via an HTTP request.
- CVE-2013-3959CVSS 4.0 · Medium
The Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, exhibits different behavior for NetBIOS user names dependin…