#VU14416 Privilege escalation in SIMATIC WinCC (TIA Portal) and SIMATIC STEP 7 (TIA Portal) - CVE-2018-11454
Published: August 15, 2018
SIMATIC WinCC (TIA Portal)
SIMATIC STEP 7 (TIA Portal)
Siemens
Description
The vulnerability allows a remote attacker to gain elevated privileges on the target system.
The vulnerability exists due to improper file permissions in the default installation of TIA Portal. A local unauthenticated attacker can transfer the manipulated files to a device and cause the service to crash or execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.