// For flags

CVE-2014-4686

Siemens SIMATIC WinCC Privilege Escalation

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a hardcoded encryption key, which allows remote attackers to obtain sensitive information by extracting this key from another product installation and then employing this key during the sniffing of network traffic on TCP port 1030.

La aplicación de administración del proyecto en Siemens SIMATIC WinCC anterior a 7.3, utilizado en PCS7 y otros productos, tiene una clave de codificación embebida, lo que permite a atacantes remotos obtener información sensible mediante la extracción de esta clave de otra instalación del producto y la posterior utilización de esta clave durante la captura de trafico de la red en puerto TCP 1030.

The latest update for SIMATIC WinCC (TIA Portal) V13 fixes two vulnerabilities. The remote management module of WinCC (TIA Portal) Multi Panels and Comfort Panels, and WinCC RT Advanced transmits weakly protected credentials over the network. Attackers capturing network traffic of the remote management module could possibly reconstruct used passwords. A hard coded encryption key used in WinCC RT Professional could allow attackers to escalate their privileges if the application's network communication with an authenticated user was captured.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-06-28 CVE Reserved
  • 2014-07-24 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Siemens
Search vendor "Siemens"
Simatic Pcs7
Search vendor "Siemens" for product "Simatic Pcs7"
<= 8.0
Search vendor "Siemens" for product "Simatic Pcs7" and version " <= 8.0"
sp1
Affected
Siemens
Search vendor "Siemens"
Simatic Pcs7
Search vendor "Siemens" for product "Simatic Pcs7"
7.1
Search vendor "Siemens" for product "Simatic Pcs7" and version "7.1"
sp3
Affected
Siemens
Search vendor "Siemens"
Simatic Pcs7
Search vendor "Siemens" for product "Simatic Pcs7"
8.0
Search vendor "Siemens" for product "Simatic Pcs7" and version "8.0"
-
Affected
Siemens
Search vendor "Siemens"
Wincc
Search vendor "Siemens" for product "Wincc"
<= 7.2
Search vendor "Siemens" for product "Wincc" and version " <= 7.2"
-
Affected
Siemens
Search vendor "Siemens"
Wincc
Search vendor "Siemens" for product "Wincc"
5.0
Search vendor "Siemens" for product "Wincc" and version "5.0"
-
Affected
Siemens
Search vendor "Siemens"
Wincc
Search vendor "Siemens" for product "Wincc"
5.0
Search vendor "Siemens" for product "Wincc" and version "5.0"
sp1
Affected
Siemens
Search vendor "Siemens"
Wincc
Search vendor "Siemens" for product "Wincc"
6.0
Search vendor "Siemens" for product "Wincc" and version "6.0"
-
Affected
Siemens
Search vendor "Siemens"
Wincc
Search vendor "Siemens" for product "Wincc"
6.0
Search vendor "Siemens" for product "Wincc" and version "6.0"
sp2
Affected
Siemens
Search vendor "Siemens"
Wincc
Search vendor "Siemens" for product "Wincc"
6.0
Search vendor "Siemens" for product "Wincc" and version "6.0"
sp3
Affected
Siemens
Search vendor "Siemens"
Wincc
Search vendor "Siemens" for product "Wincc"
6.0
Search vendor "Siemens" for product "Wincc" and version "6.0"
sp4
Affected
Siemens
Search vendor "Siemens"
Wincc
Search vendor "Siemens" for product "Wincc"
7.0
Search vendor "Siemens" for product "Wincc" and version "7.0"
-
Affected
Siemens
Search vendor "Siemens"
Wincc
Search vendor "Siemens" for product "Wincc"
7.0
Search vendor "Siemens" for product "Wincc" and version "7.0"
sp1
Affected
Siemens
Search vendor "Siemens"
Wincc
Search vendor "Siemens" for product "Wincc"
7.0
Search vendor "Siemens" for product "Wincc" and version "7.0"
sp2
Affected
Siemens
Search vendor "Siemens"
Wincc
Search vendor "Siemens" for product "Wincc"
7.0
Search vendor "Siemens" for product "Wincc" and version "7.0"
sp3
Affected
Siemens
Search vendor "Siemens"
Wincc
Search vendor "Siemens" for product "Wincc"
7.1
Search vendor "Siemens" for product "Wincc" and version "7.1"
-
Affected
Siemens
Search vendor "Siemens"
Wincc
Search vendor "Siemens" for product "Wincc"
7.1
Search vendor "Siemens" for product "Wincc" and version "7.1"
sp1
Affected