Unrated severityNVD Advisory· Published Jul 24, 2014· Updated May 6, 2026
CVE-2014-4685
CVE-2014-4685
Description
Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveraging weak system-object access control.
Affected products
16cpe:2.3:a:siemens:simatic_pcs7:7.1:sp3:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:siemens:simatic_pcs7:7.1:sp3:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_pcs7:8.0:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_pcs7:*:sp1:*:*:*:*:*:*range: <=8.0
cpe:2.3:a:siemens:wincc:*:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:siemens:wincc:*:*:*:*:*:*:*:*range: <=7.2
- cpe:2.3:a:siemens:wincc:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:5.0:sp1:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:6.0:sp2:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:6.0:sp3:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:6.0:sp4:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.0:sp1:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.0:sp2:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.0:sp3:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.1:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.1:sp1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.