CVE-2014-4685: Siemens SIMATIC PCS7

Medium severity, CVSS 4.6. EPSS: 0.4% chance of exploitation in the next 30 days.

Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveraging weak system-object access control.

Affected products

  • Siemens SIMATIC PCS7: up to and including 8.0; version 7.1 only; version 8.0 only
  • Siemens Wincc: up to and including 7.2; version 5.0 only; version 6.0 only; version 7.0 only; version 7.1 only

Published 2014-07-24. Last modified 2026-06-17.