Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-6867


A vulnerability was discovered in Siemens SIMATIC WinCC (V7.3 before Upd 11 and V7.4 before SP1), SIMATIC WinCC Runtime Professional (V13 before SP2 and V14 before SP1), SIMATIC WinCC (TIA Portal) Professional (V13 before SP2 and V14 before SP1) that could allow an authenticated, remote attacker who is member of the "administrators" group to crash services by sending specially crafted messages to the DCOM interface.


Published

2017-05-11T10:29:00.260

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 4.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-787
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application siemens simatic_wincc 7.3 Yes
Application siemens simatic_wincc 7.4 Yes
Application siemens simatic_wincc_\(tia_portal\) 13 Yes
Application siemens simatic_wincc_\(tia_portal\) 14 Yes
Application siemens simatic_wincc_runtime 13 Yes
Application siemens simatic_wincc_runtime 14 Yes

References