CVE-2014-4685

Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveraging weak system-object access control.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.6 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
VendorProductVersion
siemenssimatic_pcs7
𝑥
≤ 8.0
siemenssimatic_pcs7
7.1:sp3
siemenssimatic_pcs7
8.0
siemenswincc
𝑥
≤ 7.2
siemenswincc
5.0
siemenswincc
5.0:sp1
siemenswincc
6.0
siemenswincc
6.0:sp2
siemenswincc
6.0:sp3
siemenswincc
6.0:sp4
siemenswincc
7.0
siemenswincc
7.0:sp1
siemenswincc
7.0:sp2
siemenswincc
7.0:sp3
siemenswincc
7.1
siemenswincc
7.1:sp1
𝑥
= Vulnerable software versions
Common Weakness Enumeration