CVE-2017-14023

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
06/11/2017
Last modified:
13/05/2026

Description

An Improper Input Validation issue was discovered in Siemens SIMATIC PCS 7 V8.1 prior to V8.1 SP1 with WinCC V7.3 Upd 13, and V8.2 all versions. The improper input validation vulnerability has been identified, which may allow an authenticated remote attacker who is a member of the administrators group to crash services by sending specially crafted messages to the DCOM interface.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:siemens:simatic_pcs7:8.1:-:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_wincc:7.3:update13:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_pcs7:8.2:-:*:*:*:*:*:*