CVE-2017-14023
CVE-2017-14023
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 3.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
06 Nov 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An Improper Input Validation issue was discovered in Siemens SIMATIC PCS 7 V8.1 prior to V8.1 SP1 with WinCC V7.3 Upd 13, and V8.2 all versions. The improper input validation vulnerability has been identified, which may allow an authenticated remote attacker who is a member of the administrators group to crash services by sending specially crafted messages to the DCOM interface.
Affected products
n/a · Siemens SIMATIC PCS 7Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →