Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-14023

Опубликовано: 06 нояб. 2017
Источник: nvd
CVSS3: 4.9
CVSS2: 4
EPSS Низкий

Описание

An Improper Input Validation issue was discovered in Siemens SIMATIC PCS 7 V8.1 prior to V8.1 SP1 with WinCC V7.3 Upd 13, and V8.2 all versions. The improper input validation vulnerability has been identified, which may allow an authenticated remote attacker who is a member of the administrators group to crash services by sending specially crafted messages to the DCOM interface.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:siemens:simatic_pcs7:8.1:-:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_wincc:7.3:update13:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:siemens:simatic_pcs7:8.2:-:*:*:*:*:*:*

EPSS

Процентиль: 86%
0.02765
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-20
CWE-20

Связанные уязвимости

CVSS3: 4.9
github
больше 3 лет назад

An Improper Input Validation issue was discovered in Siemens SIMATIC PCS 7 V8.1 prior to V8.1 SP1 with WinCC V7.3 Upd 13, and V8.2 all versions. The improper input validation vulnerability has been identified, which may allow an authenticated remote attacker who is a member of the administrators group to crash services by sending specially crafted messages to the DCOM interface.

EPSS

Процентиль: 86%
0.02765
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-20
CWE-20