Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2017-14023 Details

Description

An Improper Input Validation issue was discovered in Siemens SIMATIC PCS 7 V8.1 prior to V8.1 SP1 with WinCC V7.3 Upd 13, and V8.2 all versions. The improper input validation vulnerability has been identified, which may allow an authenticated remote attacker who is a member of the administrators group to crash services by sending specially crafted messages to the DCOM interface.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://ics-cert.us-cert.gov/advisories/ICSA-17-306-01 CVEThird Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/101680 CVEThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039729 CVEThird Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-17-306-01 [email protected]Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/101680 [email protected]Third Party AdvisoryVDB Entry

see all 6 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-20Improper Input Validation[email protected]
CWE-20Improper Input Validation[email protected]

Affected Products

ProductVersions
siemens simatic pcs7
8.1 -
8.2 -

CPE

  • cpe:2.3:a:siemens:simatic_pcs7:8.1:-:*:*:*:*:*:*
  • cpe:2.3:a:siemens:simatic_pcs7:8.2:-:*:*:*:*:*:*

Remediation

  • No remediation found in references.
siemens simatic wincc
7.3 update13

CPE

  • cpe:2.3:a:siemens:simatic_wincc:7.3:update13:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

10 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2017-14023
NVD Published Date:
Nov 6, 2017
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2017-14023 Details - Not Deferred