Siemens SIMATIC WinCC Multiple Security Vulnerabilities
BID:55492
Info
Siemens SIMATIC WinCC Multiple Security Vulnerabilities
| Bugtraq ID: | 55492 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-3030 CVE-2012-3031 CVE-2012-3032 CVE-2012-3034 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 11 2012 12:00AM |
| Updated: | Sep 12 2012 10:50PM |
| Credit: | Denis Baranov Sergey Bobrov, Artem Chaykin, Vladimir Kochetkov, Pavel Toporkov, Timur Yunusov from Positive Technologies |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Siemens SIMATIC WinCC Multiple Security Vulnerabilities
Siemens SIMATIC WinCC is prone to information-disclosure, SQL-injection, directory-traversal, and cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
The attacker may exploit the information-disclosure issue and directory-traversal issues to gain access to sensitive information that may lead to further attacks.
The attacker may exploit the SQL-injection issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
An attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Siemens SIMATIC WinCC 7.0 SP3 and prior versions are vulnerable.
Siemens SIMATIC WinCC is prone to information-disclosure, SQL-injection, directory-traversal, and cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
The attacker may exploit the information-disclosure issue and directory-traversal issues to gain access to sensitive information that may lead to further attacks.
The attacker may exploit the SQL-injection issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
An attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Siemens SIMATIC WinCC 7.0 SP3 and prior versions are vulnerable.
Exploit / POC
Siemens SIMATIC WinCC Multiple Security Vulnerabilities
An attacker can exploit these issues with a web browser.
An attacker can exploit these issues with a web browser.
Solution / Fix
Siemens SIMATIC WinCC Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Siemens SIMATIC WinCC Multiple Security Vulnerabilities
References:
References:
- SIMATIC WinCC Homepage (Siemens)