VulnerabilityModified
CVE-2013-0674
Buffer overflow in the RegReader ActiveX control in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to execute arbitrary code via a long parameter.
MEDIUM 6.8EPSS 3.36%
Does this matter?
Lower severity and a low EPSS score (3.36%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in the RegReader ActiveX control in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to execute arbitrary code via a long parameter.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 3.36% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- siemens/simatic pcs7 · siemens/wincc
- Source
- ics-cert@hq.dhs.gov
References
- http://ics-cert.us-cert.gov/pdf/ICSA-13-079-02.pdfUS Government Resource
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-714398.pdfVendor Advisory
- http://ics-cert.us-cert.gov/pdf/ICSA-13-079-02.pdfUS Government Resource
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-714398.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.