CVE-2014-2731
critical
CVSS v3
—
CVSS v2
9.3
VIR risk
9.3
Description
Multiple unspecified vulnerabilities in the integrated web server in Siemens SINEMA Server before 12 SP1 allow remote attackers to execute arbitrary code via HTTP traffic to port (1) 4999 or (2) 80.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-364879.pdf
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| siemens | sinema_server | {"endIncluding":"12.0"} | |
References
- http://ics-cert.us-cert.gov/advisories/ICSA-14-107-01
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-364879.pdf
- http://ics-cert.us-cert.gov/advisories/ICSA-14-107-01
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-364879.pdf
Verify integrity in audit chain (admin only). AS-IS.