Siemens WinCC Multiple Security Vulnerabilities
BID:53837
Info
Siemens WinCC Multiple Security Vulnerabilities
| Bugtraq ID: | 53837 |
| Class: | Unknown |
| CVE: |
CVE-2012-2595 CVE-2012-2596 CVE-2012-2597 CVE-2012-2598 CVE-2012-3003 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2012 12:00AM |
| Updated: | Jun 06 2012 12:00AM |
| Credit: | Gleb Gritsai, Alexander Zaitsev, Sergey Scherbel, Yuri Goltsev, Dmitry Serebryannikov, Sergey Bobrov, Denis Baranov, Andrey Medov and Siemens |
| Vulnerable: |
Siemens WINCC 7.0 SP3 |
| Not Vulnerable: | |
Discussion
Siemens WinCC Multiple Security Vulnerabilities
Siemens SIMATIC WinCC Flexible is prone to multiple security vulnerabilities.
Attackers can exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, execute arbitrary code in the context of the affected application, read arbitrary files on the system, redirect users to a potentially malicious site, access or modify data of an XML document, or cause denial-of-service conditions; other attacks may also be possible.
Siemens SIMATIC WinCC Flexible is prone to multiple security vulnerabilities.
Attackers can exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, execute arbitrary code in the context of the affected application, read arbitrary files on the system, redirect users to a potentially malicious site, access or modify data of an XML document, or cause denial-of-service conditions; other attacks may also be possible.
Exploit / POC
Siemens WinCC Multiple Security Vulnerabilities
An attacker can use a Web browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
An attacker can use a Web browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Siemens WinCC Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Siemens WinCC Multiple Security Vulnerabilities
References:
References: