CVE-2012-3030
Summary
| CVE | CVE-2012-3030 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-09-18 14:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with insufficient access control, which allows remote attackers to read a (1) log file or (2) configuration file via a direct request. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Siemens | Simatic Pcs7 | 8.0 | All | All | All |
| Application | Siemens | Wincc | 5.0 | All | All | All |
| Application | Siemens | Wincc | 5.0 | sp1 | All | All |
| Application | Siemens | Wincc | 6.0 | All | All | All |
| Application | Siemens | Wincc | 6.0 | sp2 | All | All |
| Application | Siemens | Wincc | 6.0 | sp3 | All | All |
| Application | Siemens | Wincc | 6.0 | sp4 | All | All |
| Application | Siemens | Wincc | 7.0 | All | All | All |
| Application | Siemens | Wincc | 7.0 | sp1 | All | All |
| Application | Siemens | Wincc | 7.0 | sp2 | All | All |
| Application | Siemens | Wincc | All | sp3 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Siemens | af854a3a-2127-422b-91ae-364da2661108 | www.siemens.com | Patch, Vendor Advisory |
| Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | en.securitylab.ru | |
| 404 - File Not Found | CISA | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.