Siemens SIMATIC WinCC Default Password Security Bypass Vulnerability
BID:41753
Info
Siemens SIMATIC WinCC Default Password Security Bypass Vulnerability
| Bugtraq ID: | 41753 |
| Class: | Design Error |
| CVE: |
CVE-2010-2772 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2010 12:00AM |
| Updated: | Mar 19 2015 09:27AM |
| Credit: | Siemens |
| Vulnerable: |
Siemens SIMATIC WinCC 6.2 Siemens SIMATIC WinCC 0 |
| Not Vulnerable: | |
Discussion
Siemens SIMATIC WinCC Default Password Security Bypass Vulnerability
Siemens SIMATIC WinCC is affected by a vulnerability that allows attackers to bypass security.
An attacker can exploit this issue to bypass certain security restrictions and gain access to the application's database. Successfully exploiting this issue may lead to further attacks.
Siemens SIMATIC WinCC is affected by a vulnerability that allows attackers to bypass security.
An attacker can exploit this issue to bypass certain security restrictions and gain access to the application's database. Successfully exploiting this issue may lead to further attacks.
Exploit / POC
Siemens SIMATIC WinCC Default Password Security Bypass Vulnerability
An attacker can use readily available tools to exploit this issue.
This issue is being exploited in the wild with W32.Stuxnet (previously known as W32.Temphid).
An attacker can use readily available tools to exploit this issue.
This issue is being exploited in the wild with W32.Stuxnet (previously known as W32.Temphid).
Solution / Fix
Siemens SIMATIC WinCC Default Password Security Bypass Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Siemens SIMATIC WinCC Default Password Security Bypass Vulnerability
References:
References:
- Default SQL username and password in HMI (Que_Ball )
- SIMATIC PCS 7: Information concerning Malware / Virus / Trojan (Siemens)
- SIMATIC WinCC Homepage (Siemens)
- Wincc Database problem (Duncan)