← Back

CVE-2017-6867

nvd nist
Published: May 11, 2017Modified: May 13, 2026

JSON object

Loading...
4.9
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.2 / Impact: 3.6
Source: NVD

Description

A vulnerability was discovered in Siemens SIMATIC WinCC (V7.3 before Upd 11 and V7.4 before SP1), SIMATIC WinCC Runtime Professional (V13 before SP2 and V14 before SP1), SIMATIC WinCC (TIA Portal) Professional (V13 before SP2 and V14 before SP1) that could allow an authenticated, remote attacker who is member of the "administrators" group to crash services by sending specially crafted messages to the DCOM interface.

Affected (6)

3 products
Simatic Wincc
Simatic Wincc (tia Portal)
Simatic Wincc Runtime
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Siemens
Version 7.3
Version 7.4
Siemens
Version 13 sp1
Version 14
Siemens
Version 13 sp1
Version 14

References (6)

Source: productcert@siemens.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.