Unrated severityNVD Advisory· Published Jul 24, 2014· Updated Jun 17, 2026
CVE-2014-4686
CVE-2014-4686
Description
The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a hardcoded encryption key, which allows remote attackers to obtain sensitive information by extracting this key from another product installation and then employing this key during the sniffing of network traffic on TCP port 1030.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17cpe:2.3:a:siemens:simatic_pcs7:*:sp1:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:siemens:simatic_pcs7:*:sp1:*:*:*:*:*:*range: <=8.0
- cpe:2.3:a:siemens:simatic_pcs7:7.1:sp3:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_pcs7:8.0:*:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:*:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:siemens:wincc:*:*:*:*:*:*:*:*range: <=7.2
- cpe:2.3:a:siemens:wincc:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:5.0:sp1:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:6.0:sp2:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:6.0:sp3:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:6.0:sp4:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.0:sp1:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.0:sp2:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.0:sp3:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.1:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.1:sp1:*:*:*:*:*:*
- (no CPE)range: <7.3
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.