Siemens SIMATIC WinCC Flexible Runtime 'HmiLoad.exe' Multiple Security Vulnerabilities
BID:50828
Info
Siemens SIMATIC WinCC Flexible Runtime 'HmiLoad.exe' Multiple Security Vulnerabilities
| Bugtraq ID: | 50828 |
| Class: | Unknown |
| CVE: |
CVE-2011-4875 CVE-2011-4876 CVE-2011-4877 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2011 12:00AM |
| Updated: | Apr 18 2012 09:20PM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
Siemens SIMATIC WinCC flexible Runtime 0 Siemens SIMATIC WinCC Flexible 2008 SP2 Siemens SIMATIC WinCC Flexible 2008 SP1 Siemens SIMATIC WinCC Flexible 2008 Siemens SIMATIC WinCC Flexible 2007 Siemens SIMATIC WinCC Flexible 2005 SP1 Siemens SIMATIC WinCC Flexible 2005 Siemens SIMATIC WinCC Flexible 2004 |
| Not Vulnerable: | |
Discussion
Siemens SIMATIC WinCC Flexible Runtime 'HmiLoad.exe' Multiple Security Vulnerabilities
Siemens SIMATIC WinCC Flexible is prone to multiple security vulnerabilities that affect the 'HmiLoad.exe' program.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application, read/write or delete arbitrary files outside of the server root directory, or cause denial-of-service conditions; other attacks may also be possible.
Siemens SIMATIC WinCC Flexible is prone to multiple security vulnerabilities that affect the 'HmiLoad.exe' program.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application, read/write or delete arbitrary files outside of the server root directory, or cause denial-of-service conditions; other attacks may also be possible.
Exploit / POC
Siemens SIMATIC WinCC Flexible Runtime 'HmiLoad.exe' Multiple Security Vulnerabilities
The researcher has created exploits for these issues. Please see the references for more information.
The researcher has created exploits for these issues. Please see the references for more information.
Solution / Fix
Siemens SIMATIC WinCC Flexible Runtime 'HmiLoad.exe' Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Siemens SIMATIC WinCC Flexible Runtime 'HmiLoad.exe' Multiple Security Vulnerabilities
References:
References: