VulnerabilityModified
CVE-2013-0675
Buffer overflow in CCEServer (aka the central communications component) in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to cause a denial of service via a crafted packet.
MEDIUM 6.1EPSS 1.05%
Does this matter?
Lower severity and a low EPSS score (1.05%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in CCEServer (aka the central communications component) in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to cause a denial of service via a crafted packet.
- CVSS 2.0
- 6.1 MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 1.05% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- siemens/simatic pcs7 · siemens/wincc
- Source
- ics-cert@hq.dhs.gov
References
- http://ics-cert.us-cert.gov/pdf/ICSA-13-079-02.pdfUS Government Resource
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-714398.pdfVendor Advisory
- http://ics-cert.us-cert.gov/pdf/ICSA-13-079-02.pdfUS Government Resource
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-714398.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.